EY Data Breach Exposes Client Tax Information via Compromised Third‑Party Support Ticket System
What Happened — Attackers accessed a third‑party IT support ticket platform used by Ernst & Young from March 28 to April 12, downloading client tax‑related records. The breach was disclosed in notices filed with California, Massachusetts and Vermont attorneys‑general.
Why It Matters for Compliance & Audit Readiness —
- Shows why SOC 2 vendor‑management controls must require continuous monitoring of third‑party access and immutable logging.
- Illustrates how a supply‑chain breach can trigger a data‑exposure event, demanding auditable evidence of due‑diligence and a tested incident‑response plan.
- Reinforces the need for a documented, testable vendor‑risk program to satisfy Trust Services Criteria for security and confidentiality.
Who Is Affected — Professional‑services firms (Big Four accounting) and the corporate clients whose tax data were stored in the ticket system.
Recommended Actions —
- Review and tighten contracts with third‑party support providers to embed SOC 2 audit clauses and right‑to‑audit language.
- Deploy continuous‑monitoring solutions that capture vendor login activity, generate immutable logs, and feed directly into your audit evidence repository.
- Update your incident‑response playbook to cover third‑party platform compromises and ensure timely client notification. Source: ZDNet article
Technical Notes — The intrusion leveraged unauthorized access to a cloud‑based ticketing service; no malware, CVE or specific vulnerability was disclosed. Exfiltrated data likely included names, addresses, Social Security numbers, and financial details used for tax filings. Source: ZDNet article