Between 2015 and 2017, KPMG executives recruited former employees of the PCAOB — the body that inspects auditors — to steal confidential data revealing which audits would be inspected next. They used this to prepare in advance and "game the system." Five people were charged with conspiracy and wire fraud. KPMG's former head of National Office was sentenced to prison. $50 million penalty.[17]
The auditor cheated the audit of the auditor.
For nearly a decade, EY gave Wirecard clean audit opinions. To verify the existence of €1.9 billion supposedly held at a Singapore bank, EY relied on screenshots and documents provided by Wirecard itself. They never called the bank. The bank later said the account never existed. The German watchdog found EY's work "grossly negligent." Wirecard collapsed. €24 billion in value erased.[7]
During spot checks on KPMG's audit of Carillion, staff manufactured fake evidence and presented it as documents that had been "through oversight not included on the audit file." The FRC Tribunal was unequivocal: "No accountant should require any education or training to realise that deliberately misleading anyone, but especially a regulator, is at least incompatible with integrity."[18]
Months later, Carillion collapsed with £7 billion in liabilities. KPMG's CEO called the audit work "very bad" and said he "simply cannot defend" it.[9]
EY audited Lehman Brothers for years. They were aware of Repo 105 — a scheme to disguise repurchase agreements as sales to hide billions in debt. A Lehman VP warned EY directly. EY failed to alert the board. The bankruptcy examiner concluded EY's failure "amounted to negligence and malpractice." Then the global financial system collapsed. $99 million settlement.[13]
This is not a metaphor. EY was fined $100 million by the SEC — the largest fine ever imposed on an audit firm — after at least 49 auditors shared answer keys to CPA ethics exams. Hundreds more cheated on continuing education. EY then withheld evidence of the cheating from SEC investigators, which doubled the penalty.[15]
The PCAOB separately fined Deloitte, PwC, and EY a combined $8.5 million for widespread exam cheating in the Netherlands alone. Hundreds of professionals including senior leaders cheated over five years.[16]
The firms that can't pass their own integrity tests are the ones certifying your VPN, your password manager, your cloud storage, and your browser.
KPMG gave VBS Mutual Bank a clean bill of health in 2017. Months later, it collapsed with R2 billion looted. The independent investigator concluded the looting "would not have been possible had KPMG not signed off on the bank's financial results" and that the KPMG auditor was "complicit in the cover-up." The audit partner was debarred for life.[14]
Every "independently audited" claim follows the same chain. At every link, the conflict of interest is structural:
The Big Four audit 97% of US market capitalisation and 99% of the S&P 500.[5] There is no alternative market. The regulator cannot revoke their licences because the economy depends on them. They know this. The fines are a cost of business — a fraction of their $180 billion in combined annual revenue.
The Project On Government Oversight calls this "Accounting's Big Lie": "The audit firms are not independent — they are dependent."[4]
The privacy audit standard (ISAE 3000) has no prescriptive methodology. Scope is negotiated with the client. Many reports provide only "limited assurance" — the negative statement "nothing came to our attention." Companies rarely disclose which level of assurance they obtained. The same standard is used across VPNs, cloud storage, and financial services.[1][2]
Deloitte's 2023 NordVPN audit ran 30 November to 7 December — eight days to verify year-round no-logs claims. Fewer than 40% of VPN vendors undergo genuine third-party audits, yet almost all claim privacy protections.[3]
Consumer Reports tested 16 VPNs and found 12 either inaccurately represented their products or made hyperbolic claims. Six were vulnerable to brute force attacks.[6]
The pattern repeats across categories. EY audits Google Chrome, Gmail, Google Drive, and Microsoft 365. Deloitte audits Facebook. The same firms whose financial audits missed billions in fraud are now certifying privacy and security controls across the products people use every day.
| Firm | Case | What they missed | Consequence |
|---|---|---|---|
| EY | Wirecard (2020) | €1.9B that didn't exist. Decade of clean opinions.[7] | EY banned 2 years in Germany. |
| PwC | Evergrande (2024) | "Turned a blind eye." 14 years of auditing.[8] | $62.2M fine + 6-month China ban. |
| KPMG | Carillion (2018) | £7B in liabilities. Clean opinion months before collapse.[9] | £21.4M fine. |
| EY | NMC Health (2020) | $4B hidden debt. Management picked its own audit samples.[10] | £105.5M settlement. |
| Deloitte | Autonomy/HP (2011) | £118M hidden losses. "Serious and serial failures."[11] | $8.8B HP writedown. |
| PwC | Satyam (2009) | Fictitious assets. SEC: "much larger quality control failure."[12] | 2-year India audit ban. |
| EY | Lehman (2008) | Knew about Repo 105 debt-hiding. Said nothing.[13] | $109M in settlements. |
| KPMG | VBS Bank SA (2018) | R2B looted. Auditor "complicit in cover-up."[14] | Partner debarred for life. |
In Australia, the Big Four don't just miss fraud. They leak government secrets, suppress reports on illegal welfare schemes, and fabricate academic citations — all while collecting $3.2 billion in federal contracts over five years.[26]
PwC's head of international tax signed three confidentiality agreements with Treasury, then leaked confidential briefings on new anti-avoidance tax laws to 143 PwC partners. They used the leaks to contact 23 US tech companies — including Google, Uber, and Facebook — on how to dodge the laws before they were even publicly announced.[19][20]
CEO resigned. 12 partners forced out. AFP criminal investigation. PwC sold its government arm for $1. Revenue fell 26%. The Senate titled its report "A calculated breach of trust." Despite the purported ban, PwC and its successor held $138 million in federal contracts.[21][22]
PwC was paid ~$1 million to review the Robodebt scheme. The DHS Secretary told PwC partner Terry Weber the report "was not to be finalised." PwC delivered an 8-page PowerPoint instead of the contracted 70-page report, billed the full amount, and the illegal scheme continued for two more years. Hundreds of thousands of people received unlawful debts. $1.8 billion class action settlement.[23]
KPMG allegedly shared confidential Lendlease board papers to win Westpac and Dexus audit tenders. Same pattern as PwC — using confidential information for commercial advantage. CEO and top auditor resigned. ASIC investigating. $650 million in federal contracts at risk.[24]
Deloitte used GPT-4o to write a 237-page "independent assurance review" of an automated welfare penalty system. The report contained fabricated academic citations and invented court references. Caught not by Deloitte's quality controls, but by a University of Sydney researcher. Deloitte refunded $97K of $440K. Did not disclose AI use.[25]
A $100 million KPMG Defence contract revealed governance failures so casual that officials congratulated themselves for not recording minutes of a meeting. The "only negative" noted was that "the donuts arrived too early."[26]
We track Big Four audit involvement across 14 product categories. The same firms appear everywhere:
| Category | Product | Auditor | Standard | Assurance |
|---|---|---|---|---|
| VPN | ExpressVPN | KPMG | ISAE 3000 | Limited |
| NordVPN | Deloitte | ISAE 3000 | Limited | |
| PIA | Deloitte | ISAE 3000 | Limited | |
| Surfshark | Deloitte | ISAE 3000 | Limited | |
| Cloud Storage | Tresorit | EY | ISAE 3000 | Reasonable |
| Google Drive | EY | SOC 2 / ISO 27001 | — | |
| Dropbox | EY | SOC 2 Type II | — | |
| Browser | Google Chrome | EY | SOC 2 Type II | — |
| Gmail | EY | SOC 2 / ISO 27001 | — | |
| Productivity | Microsoft 365 | EY | SOC 2 / ISO 27001 | — |
| Social Media | Deloitte | SOC 2 Type II | — | |
| Finance | Wise | Deloitte | SOC 2 Type II | — |
Every VPN audit above used limited assurance — the lowest level. Tresorit is the only product with reasonable assurance. EY alone audits Google Chrome, Gmail, Google Drive, Dropbox, and Microsoft 365 — a single firm certifying the security of products used by billions. Products not listed (Mullvad, Proton VPN, Bitwarden, Signal, Firefox) use specialist auditors or open-source code instead. See individual category pages for full audit comparisons: VPN, password manager, cloud storage, browser, email, finance.
If Big Four stamps don't verify privacy claims, what does?
| Mechanism | Type | Why it's stronger | Examples |
|---|---|---|---|
| Open-source code | Verifiable | Anyone can inspect. Backdoors visible. | Mullvad, Bitwarden, Signal, Firefox |
| Court-tested claims | Adversarial | Subpoena or seizure returned zero data. | PIA (FBI subpoena), ExpressVPN (Turkey seizure) |
| Specialist security audit | Technical | Pen testing + source code review. Finds real bugs. | Cure53 (Mullvad, 1Password), NCC Group (Signal) |
| Bug bounty | Continuous | Crowdsourced. Ongoing. Pays for results. | ExpressVPN ($100K), 1Password (Bugcrowd) |
| RAM-only servers | Hardware | Logging physically impossible. | ExpressVPN, Mullvad, PIA |
| Zero-knowledge architecture | Structural | Provider mathematically cannot access data. | Tresorit, Bitwarden, Proton Mail |
| Big Four compliance audit | Cooperative | 8-day snapshot. Scope controlled by client. | KPMG/Deloitte ISAE 3000, EY SOC 2 |
Open-source code + specialist security audit + bug bounty + structural privacy guarantees. Verifiable trust, adversarial testing, continuous monitoring, and architecture that makes privacy violations impossible. No Big Four stamp needed.
Products like Mullvad VPN, Bitwarden, and Signal achieve this across different categories. None has ever cited a Big Four audit.
DeviceGuardian treats Big Four audits as one data point, not as proof. We weight observed behaviour over stated claims, court tests over paid audits, open-source code over compliance stamps, and who owns the company over who audited it.
A Deloitte stamp does not prevent a low grade — in any category. A product without a Big Four audit can earn a strong grade through open-source transparency, adversarial testing, and architecture that makes privacy violations physically impossible.
The firms investigated here — Deloitte, KPMG, PwC, and EY — have full entity pages documenting their inherited risks. When their names appear in product findings across our database, they link directly to these pages.
© 2026 DeviceGuardian — arewescrewed.org