Ernst & Young (EY) Investigates Data Breach Involving Third‑Party Support Tickets
What Happened — Ernst & Young disclosed that attackers accessed its third‑party support ticket system, exfiltrating client‑related data from several support cases. The breach was traced to compromised credentials of a managed‑service provider that handled EY’s ticket triage.
Why It Matters for Compliance & Audit Readiness
- A SOC 2‑ready organization must demonstrate vendor‑risk controls (CC6.1, CC6.2) and maintain continuous evidence that third‑party access is limited, monitored, and reviewed.
- The incident shows how a single supplier failure can create a data‑exposure event, underscoring the need for real‑time vendor‑risk monitoring as audit‑ready evidence.
Who Is Affected — Professional services firms, consulting firms, and any enterprise that outsources ticket or support functions to third‑party providers.
Recommended Actions
- Map the incident to SOC 2 Vendor Management controls (CC6.1 – CC6.2) and verify that contracts include breach‑notification clauses.
- Deploy continuous monitoring of third‑party access logs and integrate them into your audit evidence repository.
Technical Notes — The attackers leveraged stolen credentials from a Managed Service Provider (MSP) to log into EY’s ticketing portal, extracting PDFs and email excerpts containing client identifiers. No public CVE is associated; the vector is credential compromise. Source: [Security Affairs newsletter]