Ernst & Young is notifying customers of a data breach stemming from a compromised third-party support ticket system used by its IT personnel. The breach exposed customer information stored within the platform.
Ernst & Young (EY), one of the Big Four accounting and consulting firms, disclosed the security incident after threat actors gained unauthorized access to a third-party support system. The platform, used internally by EY's IT staff to manage technical support tickets, contained customer data.
The breach notification indicates that attackers exploited vulnerabilities in the support system to access sensitive information. EY has begun contacting affected customers and is working with cybersecurity experts to investigate the scope and nature of the exposed data.
Third-party support systems have become frequent attack vectors for cybercriminals seeking to compromise large organizations. These platforms often maintain elevated access privileges and store sensitive client information, making them attractive targets. The incident highlights ongoing risks associated with managing security across vendor ecosystems.
EY has not disclosed the specific volume of records affected or detailed timelines for when the breach occurred and was discovered. The firm stated it is implementing additional security measures and recommending customers review their accounts for suspicious activity.
This breach adds to a growing list of major corporations experiencing data compromises through external service providers. Similar incidents at other large firms underscore the challenge of securing interconnected systems where multiple parties have access to sensitive data.
Customers affected by the breach are advised to monitor financial accounts and credit reports for fraudulent activity. EY is providing resources to assist impacted parties, though specific details remain limited as the investigation continues.
The incident reinforces the importance of organizations implementing strict access controls, regular security audits, and segmented networks to limit potential damage from vendor compromises.
A study found that 86% of licensed British gambling websites violate GDPR privacy requirements, using deceptive cookie banners to track users before obtaining consent.
Berlin's government is intensively reviewing 5.79TB of state data released by ransomware group Rhysida after refusing to pay a ransom demand. The leaked files reportedly contain sensitive information on national defense and threat response plans.
Cybercriminals are exploiting thousands of compromised small-business websites to distribute ClickFix malware payloads stored in smart contracts on the BNB Smart Chain, amplifying the reach of a known threat.
Quad9 provides an open DNS recursive service that prioritizes user privacy and security at no cost. The service blocks malware and phishing domains while maintaining minimal data collection.