The Trial Balance is CFO.com’s weekly preview of stories, stats and events to help you prepare.
Part 1 — In the wake of a breach this spring, EY says its “systems are now secure.”
EY says an “unauthorized third party” gained access to an external IT support ticket system that contained client tax information.
That’s according to a breach notification filed July 15 with the state of California. In a sample notice of breach document, EY officials said they detected “anomalous activity” on the platform on April 23. The notice said that, based on EY’s investigation, the unauthorized user accessed that platform between March 26 and April 12.
EY noted that tickets submitted on that platform by IT personnel “may include documents containing tax information.” The Big Four added that it tapped an independent cybersecurity firm to investigate the issue and to confirm that the unauthorized user’s access has stopped. “Our systems are now secure,” the company said.
“EY’s Information Security team immediately initiated its incident response procedure to determine the nature and scope of the incident, contain it, and begin remediation and recovery efforts,” the notice said.
The notice said the breach may have affected “certain financial information contained in or used to prepare tax filings,” but did not share any other details. It’s not clear if the breach extended to other states. EY didn’t respond to a request for comment on Friday.
In an email, a spokesperson for California’s attorney general said that the document is a sample notice required under state law for breaches affecting more than 500 residents.
The sample notice went on to say that EY officials are “not aware of any misuse or further exposure of your personal information as a result of this incident,” and that the firm doesn’t have “any indication your personal information was specifically targeted.”
The scope of the leak isn’t clear. The notice only said that the unauthorized third party downloaded documents “pertaining to a number of EY clients.”
The breach of EY data is just one of several high-profile cybersecurity incidents so far this year. Abbott Laboratories, for instance, on Friday said it was investigating two cyber incidents that involved unauthorized access, Reuters reported. Coca-Cola, Nike and dating platform Bumble are among other big-name companies that said they’ve been hit with cyber attacks in 2026, according to Reuters.
As businesses race to incorporate new forms of tech such as artificial intelligence, such breaches are a reminder of the many potential governance issues that may accompany them.
EY’s breach also comes as the Big Four faces mounting pressure over incidents and scandals elsewhere on the globe. Regulators in Australia, for instance, are even mulling breaking up Big Four firms due to behavior that one official described as “not fair and honest,” according to a recent Reuters report.
Part 2 — This week
Here’s a list of important market events slated for the week ahead.
Monday, July 20
Tuesday, July 21 — None scheduled
Wednesday, July 22 — None scheduled
Thursday, July 23
- Initial jobless claims, week ending July 18
Friday, July 24
- S&P flash U.S. services PMI, July
- S&P flash U.S. manufacturing PMI, July
- New home sales, June
Part 3 — Quote of the week
“At ACCA, we’ve talked about moving beyond the chief financial officer to thinking about the chief value officer. It’s about being custodians of value creation. That’s no longer just financial sustainability and financial wealth. It’s your impact on people, your impact on the environment and your broader contribution to society. We talk about people, planet and prosperity.”

Melanie Proffitt
President, Association of Chartered Certified Accountants
In a recent interview, Association of Chartered Certified Accountants President Melanie Proffitt shared why accounting still faces a talent shortage, how AI is reshaping career development and why she believes professional qualifications remain relevant throughout a finance leader’s career.