Threat Intelligence Brief
Curated summary with source attribution
Source: securityaffairs.com
Threat Risk: High
Victim: Ernst & Young (EY) clients
Incident: Unauthorized access and data theft from a third-party IT support ticket system.
Impact: Potential exposure of sensitive personal and financial tax information.
Attacker: Unidentified threat actors
Analysis: This incident underscores the systemic risk of third-party supply chain dependencies, specifically regarding ITSM platforms. Threat actors maintained access for approximately two weeks, extracting documents containing personal and financial tax data. The gap between the initial breach and detection indicates a potential lack of real-time monitoring for data exfiltration within the vendor’s environment.
Recommendations: Audit third-party service provider access controls and implement the principle of least privilege.; Enforce strict data minimization policies to prevent sensitive client data from being uploaded to support tickets.; Establish enhanced monitoring and alerting for anomalous bulk data downloads from external vendor platforms.
Source: SecurityAffairs
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source