Professional Services Giant Ernst & Young (EY) Hacked

July 17, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: linkedin.com

Threat Risk: High
Victim: Ernst & Young (EY) clients
Incident: Data breach via a third-party support platform.
Impact: Exposure of sensitive personal and financial tax information for hundreds of clients.
Attacker: Unidentified threat actors
Analysis: The breach originated from a compromise of a third-party IT service-management platform used by EY for tax services. Attackers maintained access for over two weeks, exfiltrating tax documents containing highly sensitive PII and financial data. This incident underscores how support ticket attachments can serve as a high-value target for threat actors targeting professional services.
Recommendations: Conduct a comprehensive audit of third-party vendor access and data retention policies.; Implement strict data minimization for support tickets to avoid storing sensitive financial documents.; Enforce mandatory multi-factor authentication (MFA) across all external service-management tools.
Source: LinkedIn

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *