EY Tax Data Stolen Through Third-Party Help-Desk Platform, Four States Notified

July 19, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: techtimes.com

Threat Risk: High
Victim: Ernst & Young (EY) and its clients
Incident: Unauthorized access to a third-party IT service management platform led to the theft of sensitive client tax files.
Impact: Exposure of SSNs, financial account codes, and tax filings for high-net-worth individuals and corporate clients.
Attacker: Unidentified threat actors
Analysis: This incident underscores the danger of ‘shadow archives’ created when sensitive data migrates from secure repositories to less-monitored support platforms. By attaching PII to help-desk tickets, employees inadvertently bypassed primary data controls, creating a concentrated target for attackers. The dwell time demonstrates a significant gap in visibility regarding third-party service management tools.
Recommendations: Implement strict data classification and DLP rules to prevent PII from being uploaded to ticketing systems.; Conduct regular audits of third-party SaaS platforms to identify and purge unexpected sensitive data.; Enforce rigorous access controls and monitoring for any platform capable of storing client-related attachments.
Source: TechTimes

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *