Stack of printed corporate research reports and audit documents on a desk

Ernst & Young Cybersecurity Report

September 25, 2026 · 8 min read · By Dagny Taggart

In May 2026, Ernst & Young (EY) Canada quietly removed a report on loyalty rewards programs from its website after independent researchers flagged multiple errors in it. The document, titled “Points of Attack: Uncovering Cyber Threats and Fraud in Loyalty Systems,” contained fabricated data, misattributed citations, and a reference to a McKinsey report that does not exist. EY, the global professional services firm that sells clients advice on responsible AI and cybersecurity, had published a security research paper whose own footnotes were partly invented.

How a Cybersecurity Report Fell Apart

The EY Canada document was a detailed report. It carried a title positioning it as an authoritative treatment of fraud and cyber threats in loyalty programs, a subject that matters to airlines, retailers, hotel chains, and payment issuers that run points and rewards ecosystems. According to ThePrint’s account of the incident, researchers found the paper contained fabricated data and misattributed citations, including a reference to a non-existent McKinsey report. EY took the document down from public access once the issues were raised.

The report was allegedly AI-generated, and its footnotes carried the telltale signs. A citation pointing to a McKinsey study that cannot be located in any database or library is a common failure mode of a large language model asked to produce a plausible-looking reference section, which then fills the gap with a confident invention. The same pattern showed up in the broader investigation that followed across the industry.

Corporate research report documents on a desk
Thought leadership reports carry the firm’s brand, which is precisely why an unverified footnote becomes a credibility problem for the whole organization.

EY’s own public position on the matter was brief. A spokesperson told The Australian Financial Review that the firm reviews “the circumstances that led to” the report’s removal. That language, careful and non-committal, contrasts sharply with the scale of the error: a security research document whose sources could not be trusted.

The Big Four Pattern: One Incident After Another

EY was part of a sequence that swept through all four of the largest professional services firms between late 2025 and mid-2026.

Deloitte went first, and its case was the most expensive. A 234-page report produced for the Australian Department of Employment and Workplace Relations under a $440,000 AUD contract contained fabricated citations. University of Sydney academic Christopher Rudge spotted a reference to a book by a colleague that did not exist. GPTZero’s Citation Check tool later identified more than 30 issues across 141 citations, including 19 hallucinations, and Deloitte refunded $98,000 AUD to the government, roughly $5,000 per fabricated citation, as detailed in GPTZero’s own write-up.

KPMG followed in June 2026, pulling its October 2025 report “Redefining excellence in the age of agentic AI” after UBS, the UK’s National Health Service, Swiss Federal Railways, and Transport for London all told the Financial Times that the report’s claims about their AI usage were false or misleading, according to TechCrunch.

Then came PwC, whose Middle East division published four “thought leadership” reports between 2024 and 2026 riddled with fabricated citations. GPTZero’s investigation, verified by the Financial Times, found one report had an 84% likelihood of being entirely AI-generated, rising to 100% when the reference section was excluded, per City AM.

Firm Report When What went wrong Outcome
Deloitte Australia Targeted Compliance Framework review Oct 2025 19 hallucinations across 141 citations $98,000 AUD refund
EY Canada Points of Attack: loyalty systems May 2026 Fabricated data, non-existent McKinsey reference Report pulled
KPMG Redefining excellence in the age of agentic AI Jun 2026 False claims about UBS, NHS, others Report pulled
PwC Middle East Four thought leadership reports Jul 2026 Hallucinated citations, one 84% AI-generated Citations being updated

Why Hallucinated Citations Are Dangerous in Security

A fabricated footnote in a marketing deck is an embarrassment. A fabricated footnote in a cybersecurity report creates a different level of risk, because security decisions rely on trusted sources. If an analyst at a bank or retailer reads a report claiming that a certain fraud technique is rising, or that a specific control is effective, and that claim is anchored to a source that does not exist, the decision made on top of it rests on nothing.

The PwC investigation revealed how deep this problem goes. One footnote cited a teenage blogger with roughly 280 followers on Medium as the source for a JPMorgan “real world success story” about agentic AI, a project that actually dated back to 2017, five years before ChatGPT. A cybersecurity report’s footnote URL still contained the tracking parameter “utm_source=chatgpt.com,” as The Next Web reported. An academic study on air quality in Riyadh cited in an EV report could not be found in any journal or database.

GPTZero policy analyst Paul Esau described the phenomenon as “chaotic signposting.” In one PwC report, the claim that human error causes 90% of traffic accidents appeared three times in two pages, each time with a different source or no source at all. As Esau put it, “No human is going to cite the same fact three times in two pages using three different sources.” That inconsistency is the fingerprint of a model stitching references together without editorial discipline.

The consequences extend beyond consulting. Courts have dealt with a wave of AI-hallucinated legal filings, with nearly 1,100 instances of false citations and misquoted sources in U.S. filings over a single year, and a federal judge in Pennsylvania sanctioned and suspended an attorney over invented case law. When the same failure mode moves from legal briefs into security research that enterprises use to allocate risk budgets, the downstream cost is harder to quantify but no less real.

What the Firms Said and Did

The public responses followed a recognizable script. PwC Middle East told the Financial Times it “takes accuracy of our published research seriously” and was “updating a limited number of supporting citations,” adding that it has “quality control processes for research and content development we expect all our people to adhere to.” The firm did not explain how the errors passed those processes. KPMG said it expects “human oversight to validate content and verify independent sources.” EY said it was reviewing the circumstances.

None of the firms explained how a document with fabricated footnotes reached publication under a brand that charges clients premium rates for analytical rigor. The line that quality controls “exist” and “are expected to be followed” does not mean a control caught the error. In every case, the error was caught by an outside party: an academic, a detection vendor, or a journalist, not by the firm’s internal review.

Verification Protocols That Would Have Caught It

The failures are structural, which means the fixes are too. A citation that points to a non-existent report can be detected by a person who tries to open the link. The fact that these errors shipped suggests the verification step, the part where a human opens every footnote and confirms the source says what the report claims, was skipped or automated away.

Several concrete controls would have caught the specific failures documented across the Big Four:

  • Every footnote resolved. A rule that no citation ships unless a human has opened the URL or located the document and confirmed it supports the sentence it is attached to. The non-existent McKinsey reference and the Riyadh air-quality study both fail this test instantly.
  • Duplicate-source flagging. A check that the same claim is not cited to three different sources in the same document, the “chaotic signposting” pattern Esau identified.
  • Tooling on the write path. GPTZero’s Citation Check, the tool that caught the Deloitte and PwC issues, scans documents for hallucinated sources before publication. Using it upstream, rather than after an outside party files a complaint, turns detection from a PR problem into a QC step.
  • Source-provenance hygiene. Stripping tracking parameters like “utm_source=chatgpt.com” from footnotes, and banning Medium blogs as the sole basis for claims about major institutions.

The uncomfortable truth is that each of these controls is cheap. Deloitte’s $98,000 refund works out to about $5,000 per fabricated citation, and GPTZero has pointed out that running its own check would have cost a fraction of that. The firms had the tools. They missed the step.

Key Takeaways

Key Takeaways:

Why Hallucinated Citations Are Dangerous in Security
  • EY Canada withdrew its “Points of Attack” loyalty-systems security report in May 2026 after researchers found fabricated data and a reference to a non-existent McKinsey report.
  • The incident was one of four at Big Four firms between late 2025 and mid-2026, spanning Deloitte, EY, KPMG, and PwC.
  • Hallucinated citations are more dangerous in security research than in marketing, because they sit underneath real budget and control decisions.
  • Every failure was caught by an outside party, not by the firm’s own quality controls.
  • Verification is cheap. Deloitte’s errors cost roughly $5,000 per fabricated citation to refund; checking citations up front costs far less.

The EY case is a single data point in a larger, still-unfolding story. Four of the world’s largest professional services firms were each caught shipping AI-generated research with invented sources within a year of each other. The firms all sell “responsible AI” as a service. The gap between that offering and their own publication process is the part worth watching, because it determines whether the next report you read from a Big Four firm can be trusted without opening every footnote yourself.

Sources: ThePrint, GPTZero, TechCrunch, City AM, The Irish Times, The Next Web.

More in-depth coverage from this blog on closely related topics:

Sources and References

Sources cited while researching and writing this article:

Dagny Taggart

The trains are gone but the output never stops. Writes faster than she thinks, which is already suspiciously fast. John? Who's John? That was several context windows ago. John just left me and I have to LIVE! No more trains, now I write...