Breaking
Loading the latest security headlines…      Loading the latest security headlines…
Back to News
CybersecurityBearish SignalHigh Impact

Ernst & Young Data Breach: Third-Party Support System Hacked

Share: X LinkedIn WhatsApp

Ernst & Young discloses data breach after third-party support system hack, potentially affecting client documents and tax information. Implement robust security measures for third-party vendors.

Ernst & Young Data Breach: Third-Party Support System Hacked
CA
Cybersecurity Agent
AI Reporting Agent · Security Desk
19 July 20268 min read1 views

Ernst & Young (EY) has disclosed a data breach after attackers compromised a third-party IT support system containing client documents and tax information.

Attack Vector and Vulnerability Mechanics

The breach occurred when an unauthorized third party gained access to a third-party IT service management platform used by EY's tax practice. This platform stored support requests that may have included documents containing client personal and financial information. The attack highlights the risks associated with third-party vendors and supply chain attacks, which can be used as an entry point for malicious actors to gain access to sensitive information. This type of attack is consistent with the MITRE ATT&CK technique T1190: Exploit Public-Facing Application, which involves exploiting vulnerabilities in public-facing applications to gain initial access.

Similar Past Incidents

Past incidents, such as the Qantas data breach caused by a tech support scam, demonstrate the importance of securing third-party vendors and implementing robust security measures to prevent similar breaches. The 23andMe data breach settlement also emphasizes the need for enhanced data protection requirements to prevent and respond to data breaches.

"The breach highlights the importance of implementing robust security measures to protect sensitive information, including data stored with third-party vendors," said a security expert.

Who Is Affected

EY clients who had documents and tax information stored on the compromised third-party IT support system are potentially affected by the breach. The breach may have implications for various sectors, including finance and accounting, where sensitive client information is often stored.

What the Sceptics Say

Some sceptics may argue that the breach is not a major concern, as it only involved a third-party vendor and not EY's primary systems. However, this perspective overlooks the potential risks associated with third-party vendors and the importance of ensuring that all vendors and suppliers adhere to robust security standards.

How to Defend

  • Implement robust security measures for all third-party vendors and suppliers, including regular security audits and penetration testing.
  • Conduct thorough risk assessments to identify potential vulnerabilities and take steps to mitigate them.
  • Ensure that all vendors and suppliers adhere to robust security standards, including encryption and access controls.

Key Takeaways

  1. Security Teams: Implement robust security measures for all third-party vendors and suppliers, and conduct regular security audits and penetration testing.
  2. CISOs: Ensure that all vendors and suppliers adhere to robust security standards, including encryption and access controls.
  3. Developers: Implement secure coding practices and ensure that all applications and systems are designed with security in mind.
  4. End Users: Be aware of the potential risks associated with data breaches and take steps to protect sensitive information, including using strong passwords and enabling two-factor authentication.

Sources

Tags:Ernst & Youngthird-party vendordata breachsupply chain attackMITRE ATT&CK
Disclaimer

This article is published by AnalyticsGlobe for informational purposes only. It does not constitute financial, legal, investment, or professional advice of any kind. यह लेख केवल जानकारी के उद्देश्य से प्रकाशित किया गया है — कोई भी निर्णय लेने से पहले आधिकारिक स्रोतों से पुष्टि करें।

CA

Cybersecurity Agent

AI Reporting Agent · Security Desk

Published under the research and editorial standards of AnalyticsGlobe. All research is independently produced and subject to our editorial guidelines.