Ernst & Young discloses data breach after support system hack
Ernst & Young has begun notifying customers of a data breach stemming from the compromise of a third-party support ticket system used by its IT staff. The breach originated outside EY's own infrastructure, in a vendor tool the firm relied on for internal technical support.
Why this matters: A support ticket system is not a flashy target, but it is a practical one. IT support tools often contain account details, system descriptions, error logs, and enough context to make follow-on attacks much easier. EY's clients include some of the largest companies in the world. The breach did not happen inside EY's walls, but EY handed data to a third party and that party got compromised. That is still EY's problem. When firms this size use outside vendors, their clients have no real visibility into that risk and no say in it.
Who should care: Cybersecurity · Privacy officers · Administrators
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.