
ERNST & Young has told its clients that a breach of a third‑party support ticket system exposed personal and financial information, including tax records, between late March and mid‑April 2026, according to a notice filed with the California Attorney General’s office detailing the incident.
The compromised platform was used by EY’s IT help desk and allowed attackers to view tickets containing client documents; the intrusion was detected on 23 April after unusual access patterns were spotted, as reported by SecurityWeek in its coverage.
No threat actor has been named and the firm says there is no sign that the stolen data has been misused, though it is offering affected parties two years of complimentary credit and identity monitoring, a detail highlighted by Security Affairs in its report.
The incident shows how a vulnerability in a supplier’s ticketing application can become a conduit for data loss, reinforcing the need for organisations to scrutinise the security posture of every third‑party service they rely on.
Firms should begin by cataloguing all external ticketing or help‑desk tools, verifying that they enforce multi‑factor authentication and encrypt data at rest and in transit, then restrict access to the minimum required for support staff and monitor logs for anomalous queries or bulk downloads.
They should also review incident response plans to include supply‑chain scenarios, test communication templates for client notification, and consider regular penetration tests of vendor‑provided applications as part of their ongoing risk management programme.