HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

EY Data Breach Exposes Client Tax Documents via Compromised Third‑Party Support Ticket System

Ernst & Young reported that attackers accessed a third‑party support ticket system and downloaded client tax documents between March 28 and April 12 2026. The breach highlights the need for continuous vendor‑risk monitoring and SOC 2‑ready audit evidence.

LiveThreat™ Intelligence · 📅 July 18, 2026· 📰 securityaffairs.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
securityaffairs.com

EY Data Breach Exposes Client Tax Documents via Compromised Third‑Party Support Ticket System

What Happened — Ernst & Young (EY) disclosed that attackers compromised a third‑party IT service‑management platform used for internal support tickets. Between March 28 and April 12 2026 the unauthorized party accessed the system and downloaded documents containing client tax information. EY’s security team isolated the breach on April 23 2026 and engaged an independent firm to confirm that the intrusion was stopped.

Why It Matters for Compliance & Audit Readiness

  • The incident illustrates a classic vendor‑risk scenario that SOC 2’s CC6.1 – Vendor Management control is designed to mitigate: you must assess, monitor, and obtain evidence of third‑party security posture continuously.
  • Continuous‑compliance programs need auditable proof that vendor‑risk assessments are up‑to‑date; a breach like this underscores the value of automated monitoring that feeds directly into your SOC 2 audit artifact repository.

Who Is Affected — Professional services firms (audit, tax, consulting) and their corporate clients whose tax filings were processed through EY.

Recommended Actions

  • Review and update your vendor‑risk management policy to require real‑time security monitoring of all third‑party platforms handling sensitive data.
  • Map the breach to SOC 2 CC6.1, collect evidence of due‑diligence (contracts, security questionnaires, continuous monitoring logs) and store it in your audit evidence vault.
  • Conduct a focused risk assessment of any similar ticketing or document‑exchange tools in your environment and remediate any gaps.

Source: Security Affairs

Technical Notes — The compromised system was an external IT support ticket service that stored attached client documents. No specific vulnerability (CVE) was disclosed; the breach appears to stem from unauthorized access to the third‑party platform, possibly via credential compromise or insufficient vendor controls. Source: same article

📰 Original Source
https://securityaffairs.com/195550/data-breach/ernst-young-ey-investigates-data-breach-involving-third-party-support-tickets.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

Point-in-time vendor reviews miss incidents like this.

Verisq AI Trust Operations replaces the annual questionnaire with continuous third-party monitoring — so vendor exposure becomes audit evidence, not a once-a-year guess.

See how Verisq AI Trust Operations works →