Threat Intelligence Brief
Curated summary with source attribution
Source: techtimes.com
Threat Risk: High
Victim: Ernst & Young (EY) and its clients
Incident: Unauthorized access to a third-party IT service management platform led to the theft of sensitive client tax files.
Impact: Exposure of SSNs, financial account codes, and tax filings for high-net-worth individuals and corporate clients.
Attacker: Unidentified threat actors
Analysis: This incident underscores the danger of ‘shadow archives’ created when sensitive data migrates from secure repositories to less-monitored support platforms. By attaching PII to help-desk tickets, employees inadvertently bypassed primary data controls, creating a concentrated target for attackers. The dwell time demonstrates a significant gap in visibility regarding third-party service management tools.
Recommendations: Implement strict data classification and DLP rules to prevent PII from being uploaded to ticketing systems.; Conduct regular audits of third-party SaaS platforms to identify and purge unexpected sensitive data.; Enforce rigorous access controls and monitoring for any platform capable of storing client-related attachments.
Source: TechTimes
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source