This is the most common confusion, and it has a straightforward explanation. Ernst & Young LLP provides tax services to institutional clients, such as employers and investment firms. In the course of that work it receives personal information about individuals connected to those institutions. If your information reached EY that way, you can receive a notice from a firm you never personally engaged. The letter itself describes information relating to your investment holdings with an EY client, which is why so many recipients do not recognise the connection.
So the letter is not evidence that you were an EY client, and it is not a scam simply because you do not recognize the sender. Treat it as real, and read it carefully.
Ernst & Young LLP filed a data breach notification with the California Attorney General in July 2026, and the sample notice letter is public. Everything in this section comes from that filing rather than from any news write up. You can read the filing yourself in the California Attorney General breach list.
Several things are being reported as fact that are not established, and you deserve to know which is which.
A lot of breach advice tells everyone who receives a notice to file Form 14039, the Identity Theft Affidavit. For most people that is wrong, and it clogs the process for people who genuinely need it.
Form 14039 is for people who have actually experienced tax related identity theft, for example an electronically filed return rejected because one was already filed under your Social Security number, or an IRS notice about a return you did not file. Receiving a breach letter, on its own, is not that. Get the IP PIN, stay alert, and file the affidavit only if something actually happens. The IRS explains the distinction on its identity theft central pages.
The notices are individualized. What applies to you is printed on your letter, and it is more accurate than any summary.
The letters describe 24 months of Experian IdentityWorks, enrolled with an activation code printed on your letter, with no credit card required. The sample notice puts the cutoff at 11:59 p.m. UTC on October 31, 2026. Confirm your own deadline and code on your letter rather than trusting a date you read elsewhere, including here. Identity restoration is available without enrolling.
Freezes are free, you place them separately at Equifax, Experian and TransUnion, and you can lift one temporarily when you need credit. A freeze is stronger than a fraud alert.
Anyone who has your real tax details can sound legitimate. The IRS does not initiate contact by phone, email or text demanding payment. If a caller pressures you, hang up and call the number printed on your letter or on IRS.gov.
Store it with your tax records. If anything happens later, the notice is your documentation of when your information was exposed.
The Federal Trade Commission keeps a step by step recovery tool at identitytheft.gov if you find actual misuse.
You will find law firms advertising class action investigations around this notice. That is normal after any large breach, and evaluating a claim is your decision to make. WAYG has no stake in it, earns nothing from it, and is not referring you anywhere. We mention it only so you can recognize a solicitation for what it is when you meet one.
One more point of accuracy: this is a separate matter from a report in October 2025 about an EY backup file that was briefly reachable online. Different incident, different timeline. If you see the two blended together, the write up is not being careful.
WAYG is an accounting, tax and advisory firm in Coral Gables, Florida. We wrote this because the tax specific part of breach advice is usually missing, and we happen to know it. Nothing on this page requires you to contact us.
In the interest of the same honesty we are asking for elsewhere: WAYG is not a CPA firm. Returns are prepared first party by an IRS PTIN holder with Enrolled Agent candidacy in progress, and licensed work such as audits is coordinated through our vetted partner network. We hold no security certification of our own, and we are not going to imply otherwise or claim that we would have prevented anything.
WAYG is not affiliated with, endorsed by, or sponsored by Ernst & Young LLP. Ernst & Young is named here only to identify the public breach notification being discussed. This page is general information based on public filings and government guidance as of July 2026, it is not legal or tax advice for your specific situation, and details of any incident can change as more becomes known. Always follow the instructions on your own notification letter.