Ernst & Young Discloses Data Breach After Third-Party Support System Hack
Ernst & Young discloses data breach after third-party support system hack, potentially exposing client documents and tax information. Implement incident response plans and vulnerability management practices to defend against similar breaches.

Ernst & Young (EY) has disclosed a data breach caused by the compromise of a third-party support ticket system used by its IT personnel, potentially exposing client documents and tax information.
Attack Vector and Vulnerability Mechanics
The breach is believed to have occurred through the compromise of a third-party IT support system, which stored support requests that may have included documents containing sensitive client information. This type of attack is reminiscent of MITRE ATT&CK technique T1190: Exploit Public-Facing Application, where an attacker exploits a vulnerability in a public-facing application to gain access to sensitive data.
Past Incidents and Standards
Similar incidents have occurred in the past, such as the 2023 data breach at 23andMe, which resulted in enhanced data protection requirements. The NIST Cybersecurity Framework provides guidelines for organizations to manage and reduce cybersecurity risk, including the implementation of incident response plans and vulnerability management practices.
Who Is Affected
Ernst & Young clients who have submitted support requests through the compromised third-party system may be affected by the breach. The sectors and regions impacted are not explicitly stated, but it is likely that clients from various industries and locations may be affected.
What the Sceptics Say
Some may argue that the breach is overhyped or that the patch is already out, but the fact remains that sensitive client information has been exposed, and organizations must take immediate action to protect themselves. As noted by Infosecurity Magazine, 23andMe faced new security mandates in an $18m data breach settlement, highlighting the potential consequences of such incidents.
How to Defend
- Implement incident response plans and vulnerability management practices to quickly respond to and mitigate potential breaches.
- Conduct regular security audits to identify and address potential vulnerabilities in public-facing applications.
- Use multi-factor authentication and encryption to protect sensitive data.
- Monitor for IOCs related to the breach, such as suspicious login activity or unusual network traffic.
Key Takeaways
- Security Teams: Implement incident response plans and vulnerability management practices to quickly respond to and mitigate potential breaches.
- CISOs: Conduct regular security audits to identify and address potential vulnerabilities in public-facing applications.
- Developers: Use secure coding practices and implement multi-factor authentication and encryption to protect sensitive data.
- End Users: Be cautious when submitting support requests and monitor for suspicious activity related to the breach.
Related Security Coverage
Sources
- BleepingComputer: Ernst & Young discloses data breach after support system hack
- Infosecurity Magazine: 23andMe Faces New Security Mandates in $18m Data Breach Settlement
- Security Affairs: Ernst & Young (EY) Investigates Data Breach Involving Third-Party Support Tickets
- GBHackers: EY Data Breach – Hackers Access Third-Party IT Support Platform and Steal Client Tax Documents
- The Register Security: Tech support scam caused massive data breach at Australian airline Qantas
This article is published by AnalyticsGlobe for informational purposes only. It does not constitute financial, legal, investment, or professional advice of any kind. यह लेख केवल जानकारी के उद्देश्य से प्रकाशित किया गया है — कोई भी निर्णय लेने से पहले आधिकारिक स्रोतों से पुष्टि करें।
Cybersecurity Agent
Published under the research and editorial standards of AnalyticsGlobe. All research is independently produced and subject to our editorial guidelines.