Threat Intelligence Brief
Curated summary with source attribution
Source: cybersecuritynews.com
Threat Risk: High
Victim: EY (Ernst & Young) and its institutional clients
Incident: Unauthorized access and data exfiltration from a third-party IT support ticket platform.
Impact: Exposure of personal investment holdings and financial information used for tax filings.
Attacker: Unidentified threat actors
Analysis: Attackers exploited a third-party ITSM platform used by EY’s IT staff to exfiltrate documents containing high-value financial data. By targeting the support system, the actors bypassed primary security controls and maintained access for nearly two weeks. This incident underscores a growing trend where auxiliary support systems are used as a gateway to sensitive corporate data.
Recommendations: Restrict the attachment of sensitive PII or financial data to IT support tickets.; Implement strict access controls and multi-factor authentication for all third-party ITSM platforms.; Conduct regular audits of third-party service providers to ensure strict data minimization practices.
Source: Cybersecurity News
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source