Ernst & Young Data Breach Analysis: Third-Party IT Support Platform Compromise Exposes Client Tax and Financial Information – Rescana

July 19, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: rescana.com

Threat Risk: High
Victim: Ernst & Young (EY)
Incident: Unauthorized access to a third-party IT support platform led to the theft of client tax and financial documents.
Impact: Exposure of sensitive personal and financial information for multiple EY clients.
Attacker: Unidentified threat actors
Analysis: Attackers leveraged a trusted relationship with a third-party IT service management platform to access aggregated support tickets. The breach resulted in the exfiltration of client tax documents over a two-week window. This incident underscores the danger of storing sensitive PII within support ticket attachments and the risks of vendor-managed platforms.
Recommendations: Implement strict data minimization policies to prevent PII from being stored in support ticket attachments.; Conduct rigorous and continuous security audits of third-party service providers (TPRM).; Enforce strict access controls and activity monitoring for all vendor-managed integrations.
Source: Rescana

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *