EY Data Breach – Hackers Access IT Support System and Download Documents

July 18, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: cybersecuritynews.com

Threat Risk: High
Victim: EY (Ernst & Young) and its institutional clients
Incident: Unauthorized access and data exfiltration from a third-party IT support ticket platform.
Impact: Exposure of personal investment holdings and financial information used for tax filings.
Attacker: Unidentified threat actors
Analysis: Attackers exploited a third-party ITSM platform used by EY’s IT staff to exfiltrate documents containing high-value financial data. By targeting the support system, the actors bypassed primary security controls and maintained access for nearly two weeks. This incident underscores a growing trend where auxiliary support systems are used as a gateway to sensitive corporate data.
Recommendations: Restrict the attachment of sensitive PII or financial data to IT support tickets.; Implement strict access controls and multi-factor authentication for all third-party ITSM platforms.; Conduct regular audits of third-party service providers to ensure strict data minimization practices.
Source: Cybersecurity News

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *