Ernst & Young is notifying customers of a data breach stemming from a compromised third-party support ticket system used by its IT personnel. The breach exposed customer information stored within the platform.
Ernst & Young (EY), one of the Big Four accounting and consulting firms, disclosed the security incident after threat actors gained unauthorized access to a third-party support system. The platform, used internally by EY's IT staff to manage technical support tickets, contained customer data.
The breach notification indicates that attackers exploited vulnerabilities in the support system to access sensitive information. EY has begun contacting affected customers and is working with cybersecurity experts to investigate the scope and nature of the exposed data.
Third-party support systems have become frequent attack vectors for cybercriminals seeking to compromise large organizations. These platforms often maintain elevated access privileges and store sensitive client information, making them attractive targets. The incident highlights ongoing risks associated with managing security across vendor ecosystems.
EY has not disclosed the specific volume of records affected or detailed timelines for when the breach occurred and was discovered. The firm stated it is implementing additional security measures and recommending customers review their accounts for suspicious activity.
This breach adds to a growing list of major corporations experiencing data compromises through external service providers. Similar incidents at other large firms underscore the challenge of securing interconnected systems where multiple parties have access to sensitive data.
Customers affected by the breach are advised to monitor financial accounts and credit reports for fraudulent activity. EY is providing resources to assist impacted parties, though specific details remain limited as the investigation continues.
The incident reinforces the importance of organizations implementing strict access controls, regular security audits, and segmented networks to limit potential damage from vendor compromises.
France's data protection authority (CNIL) has fined Hôpital privé de la Loire €500,000 for failing to adequately protect the personal data of 727,000 patients and their relatives.
The FBI is investigating a possible security breach at an ID verification company that may have exposed driver's license scans belonging to millions of Americans. The agency confirmed the investigation to Bloomberg News on Thursday.
Attackers compromised Coder's Cloudflare infrastructure and injected malicious Terraform modules designed to steal credentials. The unauthorized registry servers delivered the infected packages to users.
A US senator has called on the NSA to provide official guidance on virtual private network selection and usage, citing confusion over the growing array of available options.