HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

Ernst & Young (EY) Data Breach Exposes Client Support Tickets Through Compromised Third‑Party Credentials

EY reported that attackers accessed its third‑party support ticket system using stolen MSP credentials, exfiltrating client‑related data. The breach highlights the importance of SOC 2 vendor‑risk controls and continuous monitoring of third‑party access.

LiveThreat™ Intelligence · 📅 July 20, 2026· 📰 securityaffairs.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
2 recommended
📰
Source
securityaffairs.com

Ernst & Young (EY) Investigates Data Breach Involving Third‑Party Support Tickets

What Happened — Ernst & Young disclosed that attackers accessed its third‑party support ticket system, exfiltrating client‑related data from several support cases. The breach was traced to compromised credentials of a managed‑service provider that handled EY’s ticket triage.

Why It Matters for Compliance & Audit Readiness

  • A SOC 2‑ready organization must demonstrate vendor‑risk controls (CC6.1, CC6.2) and maintain continuous evidence that third‑party access is limited, monitored, and reviewed.
  • The incident shows how a single supplier failure can create a data‑exposure event, underscoring the need for real‑time vendor‑risk monitoring as audit‑ready evidence.

Who Is Affected — Professional services firms, consulting firms, and any enterprise that outsources ticket or support functions to third‑party providers.

Recommended Actions

  • Map the incident to SOC 2 Vendor Management controls (CC6.1 – CC6.2) and verify that contracts include breach‑notification clauses.
  • Deploy continuous monitoring of third‑party access logs and integrate them into your audit evidence repository.

Technical Notes — The attackers leveraged stolen credentials from a Managed Service Provider (MSP) to log into EY’s ticketing portal, extracting PDFs and email excerpts containing client identifiers. No public CVE is associated; the vector is credential compromise. Source: [Security Affairs newsletter]

📰 Original Source
https://securityaffairs.com/195611/breaking-news/security-affairs-newsletter-round-586-by-pierluigi-paganini-international-edition.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

This is the scenario continuous vendor monitoring is built to catch.

When a vendor is compromised, your SOC 2 vendor-management controls are what produce the audit trail showing you knew, assessed, and acted. The Verisq AI Trust Operations platform tracks that continuously.

Explore the Verisq AI Trust Operations platform →