HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

EY Data Breach Exposes Client Tax Information via Compromised Third‑Party Support Ticket System

Ernst & Young disclosed that attackers accessed a third‑party support ticket system from March 28‑April 12, stealing client tax‑related records. The incident underscores the need for SOC 2 vendor‑management controls and continuous monitoring of third‑party access to maintain audit readiness.

LiveThreat™ Intelligence · 📅 July 22, 2026· 📰 zdnet.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
zdnet.com

EY Data Breach Exposes Client Tax Information via Compromised Third‑Party Support Ticket System

What Happened — Attackers accessed a third‑party IT support ticket platform used by Ernst & Young from March 28 to April 12, downloading client tax‑related records. The breach was disclosed in notices filed with California, Massachusetts and Vermont attorneys‑general.

Why It Matters for Compliance & Audit Readiness

  • Shows why SOC 2 vendor‑management controls must require continuous monitoring of third‑party access and immutable logging.
  • Illustrates how a supply‑chain breach can trigger a data‑exposure event, demanding auditable evidence of due‑diligence and a tested incident‑response plan.
  • Reinforces the need for a documented, testable vendor‑risk program to satisfy Trust Services Criteria for security and confidentiality.

Who Is Affected — Professional‑services firms (Big Four accounting) and the corporate clients whose tax data were stored in the ticket system.

Recommended Actions

  • Review and tighten contracts with third‑party support providers to embed SOC 2 audit clauses and right‑to‑audit language.
  • Deploy continuous‑monitoring solutions that capture vendor login activity, generate immutable logs, and feed directly into your audit evidence repository.
  • Update your incident‑response playbook to cover third‑party platform compromises and ensure timely client notification. Source: ZDNet article

Technical Notes — The intrusion leveraged unauthorized access to a cloud‑based ticketing service; no malware, CVE or specific vulnerability was disclosed. Exfiltrated data likely included names, addresses, Social Security numbers, and financial details used for tax filings. Source: ZDNet article

📰 Original Source
https://www.zdnet.com/article/ernst-young-breach-exposed-client-tax-data/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

Point-in-time vendor reviews miss incidents like this.

Verisq AI Trust Operations replaces the annual questionnaire with continuous third-party monitoring — so vendor exposure becomes audit evidence, not a once-a-year guess.

See how Verisq AI Trust Operations works →