PrivacySignal
Breach

Ernst & Young discloses data breach after support system hack

BleepingComputer · · International · Data Breaches

Ernst & Young has begun notifying customers of a data breach stemming from the compromise of a third-party support ticket system used by its IT staff. The breach originated outside EY's own infrastructure, in a vendor tool the firm relied on for internal technical support.

Why this matters: A support ticket system is not a flashy target, but it is a practical one. IT support tools often contain account details, system descriptions, error logs, and enough context to make follow-on attacks much easier. EY's clients include some of the largest companies in the world. The breach did not happen inside EY's walls, but EY handed data to a third party and that party got compromised. That is still EY's problem. When firms this size use outside vendors, their clients have no real visibility into that risk and no say in it.

Who should care: Cybersecurity · Privacy officers · Administrators

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

Breach
BleepingComputer · · International

Microsoft warns of TerminalFix attacks deploying reverse tunnels

A new ClickFix variant dubbed TerminalFix uses fake Cloudflare CAPTCHA prompts on compromised websites to trick victims into running malicious PowerShell commands in Windows Terminal. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
DataBreaches.net · · International

A rough day at the extortion office and a botched attack on Blossom Health.

An apparent extortionist targeted Blossom Health, a US telehealth and psychiatry platform, by compromising either the platform itself or an individual provider's account and sending what appears to be a ransom demand. The incident came to light after a patient contacted DataBreaches directly to report it.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
DataBreaches.net · · International

Time’s Up: Ransomware Group Claims 150,000+ Cardiology Patient Records. We’ve Seen the Data.

A ransomware group called Orova claims to have stolen more than 150,000 patient records from Cardiology Associates of Port Huron, a Michigan cardiology practice operating across nine locations. Journalists have reviewed the data, which reportedly contains personally identifiable and protected health information.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare#security Read original →
Breach
DataBreaches.net · · International

A massive cache of Valve data has reportedly leaked online, appearing to include Portal 2’s elusive beta build and a potential weapon from Half-Life 2: Episode 3

A large cache of internal Valve data, reportedly totaling 12 terabytes, has leaked from an unknown source and is being analyzed online. The files appear to include unreleased beta builds of several classic Valve games and possible content from the long-cancelled Half-Life 2: Episode 3.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
DataBreaches.net · · International

VT: Local VA warns of possible data breach

The VA's White River Junction, Vermont healthcare facility disclosed that unencrypted communications containing veterans' personal health information were sent in error earlier this summer. The department acknowledged the incident in a public release, confirming the exposure was unintentional.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance · General readers · Policy

#breach#healthcare#privacy Read original →