EY Discloses Data Breach of Third-Party Support System Affecting IT Personnel
AI-generated from multiple sources. Verify before acting on this reporting.
LONDON — Ernst & Young disclosed on Wednesday that unauthorized actors gained access to a third-party support ticket system used by its information technology personnel, marking the latest security incident involving one of the world's largest professional services firms. The breach occurred between March 28 and April 12, during which time attackers exploited vulnerabilities in an external platform utilized for internal IT service requests.
The accounting giant confirmed that the compromise involved a vendor-managed system rather than its core client data repositories or primary financial networks. EY stated that the incident was detected through routine monitoring of third-party access logs and immediately triggered an investigation by its cybersecurity team alongside external forensic experts. The firm emphasized that no evidence suggests unauthorized actors accessed sensitive client information, confidential audit files, or proprietary intellectual property stored on internal servers.
The support ticket system in question serves as a central hub for EY employees to log technical issues, request software access, and manage hardware maintenance. While the specific nature of the data exposed within these tickets remains under review, initial assessments indicate that personal identifiers such as employee names, job titles, and departmental contact details were potentially visible to the intruders during the 16-day window.
EY has notified relevant regulatory bodies in jurisdictions where affected employees are based. The firm is also working with law enforcement agencies to trace the origin of the intrusion and identify the threat actors responsible. In a statement released on July 17, EY leadership expressed commitment to transparency regarding the incident while assuring clients that their data remains secure.
The breach underscores growing concerns within the professional services sector about supply chain vulnerabilities. As firms increasingly rely on external vendors for operational support tools, the risk of lateral movement from third-party systems into internal networks has become a primary focus for cybersecurity strategies. EY announced it is implementing additional authentication protocols and conducting a comprehensive audit of all vendor access points to prevent similar occurrences.
Questions remain regarding the full scope of data accessed within the ticket system and whether any credentials were harvested that could facilitate future attacks on other systems. The firm has not yet determined if the attackers exfiltrated information or merely gained read-only access during their presence in the network. EY expects to provide further updates as the investigation progresses, with a focus on determining long-term remediation steps for its third-party vendor relationships.