Full Report
For the latest discoveries in cyber research for the week of 20th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Ernst & Young, a global accounting and professional services company, has disclosed a data breach involving a compromised third-party IT support platform. The exposed support tickets may have contained client documents, tax information, […] The post 20th July – Threat Intelligence Report appeared first on Check Point Research.
Analysis Summary
# Incident Report: Compromise of Third-Party IT Support Platform Affecting Ernst & Young (EY)
## Executive Summary
Global accounting firm Ernst & Young (EY) disclosed a data breach resulting from the compromise of a third-party IT support platform. The incident led to the exposure of sensitive client documents, tax information, and employee data contained within support tickets. While the third-party provider was the primary point of entry, the impact extends to EY’s global client base and internal personnel.
## Incident Details
- **Discovery Date:** July 2026 (Reported)
- **Incident Date:** Preceding July 20, 2026
- **Affected Organization:** Ernst & Young (EY)
- **Sector:** Accounting and Professional Services
- **Geography:** Global
## Timeline of Events
### Initial Access
- **Date/Time:** Not specified (Pre-July 2026)
- **Vector:** Supply Chain / Third-Party Compromise
- **Details:** Attackers gained unauthorized access to a third-party IT support platform used by EY to manage technical assistance requests.
### Lateral Movement
- **Details:** Access was confined to the third-party support ticketing environment; however, attackers were able to navigate through archived and active support tickets submitted by EY personnel and clients.
### Data Exfiltration/Impact
- **Details:** Attackers accessed and potentially exfiltrated sensitive data attached to support tickets, including:
- Client financial documents
- Detailed tax information
- Employee identification and contact details
- Technical configuration data shared during support sessions
### Detection & Response
- **How it was discovered:** Internal investigation/disclosure by the third-party provider or EY security operations.
- **Response actions taken:** EY initiated an investigation into the scope of the exposure and began the process of notifying affected clients and employees.
## Attack Methodology
- **Initial Access:** Compromise of third-party service provider (SaaS/Support Platform).
- **Persistence:** Utilization of legitimate (though compromised) administrative or user credentials on the support platform.
- **Collection:** Automated or manual harvesting of attachments and text within historical support tickets.
- **Impact:** Data breach and confidentiality loss involving sensitive PII (Personally Identifiable Information) and corporate financial data.
## Impact Assessment
- **Financial:** Potential regulatory fines (GDPR/CCPA) and costs associated with forensic audits and credit monitoring for affected parties.
- **Data Breach:** High-volume exposure of sensitive "life-of-the-business" data (tax records).
- **Operational:** Disruption to IT support workflows; requirement to migrate support services or audit third-party security.
- **Reputational:** High; EY is a "Big Four" firm whose value proposition relies heavily on the secure handling of sensitive financial data.
## Indicators of Compromise
*Note: Specific technical IOCs (hashes/IPs) were not provided in the summary report as the breach occurred at a third-party provider.*
- **Behavioral indicators:** Unusual login patterns or bulk data exports from the third-party support portal.
## Response Actions
- **Containment measures:** Isolation of the compromised third-party platform.
- **Eradication steps:** Revocation of compromised credentials and clearing of unauthorized sessions on the support portal.
- **Recovery actions:** Notification of regulatory bodies and affected clients; manual review of exposed tickets to categorize risk.
## Lessons Learned
- **Key takeaways:** Third-party support platforms often contain highly sensitive "shadow data" in the form of attachments and screenshots that may not be subject to the same lifecycle management as primary databases.
- **What could have been done better:** Implementation of stricter data retention policies for support tickets (e.g., auto-deleting attachments after 30 days) and requiring multi-factor authentication (MFA) for all third-party integrations.
## Recommendations
- **Prevention measures:**
- Encrypt or redact sensitive files before uploading them to third-party support portals.
- Conduct regular security audits of the "Supply Chain" and third-party vendors.
- Implement a "Least Privilege" access model for support desk platforms.
- Use secure file transfer protocols for sensitive documents instead of attaching them directly to support tickets.