Full Report
A data breach involving Easterly Government Properties was reported in June 2026. See incident details, impact on customers, and recommended security measures.
Analysis Summary
# Incident Report: Easterly Government Properties Third-Party Data Breach
## Executive Summary
Easterly Government Properties experienced a significant data breach originating from a third-party security incident at their tax services vendor, Ernst & Young (EY). The breach resulted in the unauthorized acquisition of sensitive PII and financial data, including Social Security numbers and taxable income records. While the organization was not the primary target, the compromise of the vendor's environment led to the exposure of Easterly’s investors and employees.
## Incident Details
- **Discovery Date:** June 15, 2026 (Reported)
- **Incident Date:** Prior to June 15, 2026
- **Affected Organization:** Easterly Government Properties (via Ernst & Young)
- **Sector:** Real Estate / Government Properties
- **Geography:** United States
## Timeline of Events
### Initial Access
- **Date/Time:** Undisclosed (Prior to June 15, 2026)
- **Vector:** Third-party compromise
- **Details:** An unidentified threat actor gained unauthorized access to the systems of EY (Ernst & Young), Easterly’s professional tax services provider.
### Lateral Movement
- **Details:** The threat actor navigated through EY’s internal environment to access specific files and records related to their professional services clients, including Easterly Government Properties.
### Data Exfiltration/Impact
- **Details:** Sensitive files were acquired by an unauthorized party. The stolen data included names, physical mailing addresses, Social Security numbers, and taxable income details.
### Detection & Response
- **How it was discovered:** Discovery occurred through EY's internal security monitoring or incident response protocols (details not publicly disclosed).
- **Response actions taken:** Easterly Government Properties officially disclosed the breach on June 15, 2026, and initiated notification procedures for affected individuals.
## Attack Methodology
- **Initial Access:** Third-party supply chain compromise (EY)
- **Persistence:** Undisclosed
- **Privilege Escalation:** Undisclosed
- **Defense Evasion:** Undisclosed
- **Credential Access:** Undisclosed
- **Discovery:** Reconnaissance of EY’s client tax records
- **Lateral Movement:** Internal movement within the vendor’s network environment
- **Collection:** Gathering of tax documents and PII
- **Exfiltration:** Unauthorized transfer of sensitive tax and identity files
- **Impact:** Data breach and identity theft risk
## Impact Assessment
- **Financial:** High risk of tax fraud and unauthorized credit account creation for affected individuals.
- **Data Breach:** Exposure of highly sensitive PII (SSNs) and financial data (taxable income).
- **Operational:** Disruption to tax service workflows and administrative burden of breach notification.
- **Reputational:** Medium; while the breach occurred at a vendor, it impacts the trust of Easterly’s investors and employees.
## Indicators of Compromise
- **Network indicators:** None disclosed in the public report.
- **File indicators:** Sensitive PDF/Excel tax documents acquired by unauthorized parties.
- **Behavioral indicators:** Unauthorized access to tax service database/file shares at EY.
## Response Actions
- **Containment measures:** EY performed isolation of affected systems (implied).
- **Eradication steps:** Dissemination of breach notices to affected parties.
- **Recovery actions:** Provision of guidance for credit monitoring and IRS Identity Protection PINs to affected individuals.
## Lessons Learned
- **Key takeaways:** Dependence on large, reputable third-party vendors (Big Four firms) does not eliminate supply chain risk.
- **What could have been done better:** Enhanced encryption of data at rest within the vendor environment and stricter access controls (Zero Trust) for sensitive tax records could have mitigated the scope.
## Recommendations
- **Vendor Risk Management:** Implement continuous monitoring of third-party security postures and audit their data retention/access policies.
- **Identity Protection:** Advise all employees and investors to place a credit freeze and apply for an IRS IP PIN.
- **Security Awareness:** Train staff to recognize phishing attempts that may leverage the specific leaked details (e.g., mailing addresses and income info) to appear legitimate.