Back to all lessons
Awareness Lessons
3 months ago

EY Data Breach Exposes Client Tax Data via Third-Party Support System

Ernst & Young suffered a data breach through a third-party IT support ticketing system, exposing sensitive personal and financial data from client tax documents for over two weeks before discovery. The root issue lies in inadequate oversight and security controls applied to third-party vendor platforms that handle highly sensitive client data. Large professional services firms often extend implicit trust to support tooling without enforcing the same security standards required of core systems. This incident underscores that regulated financial and personal data must be protected regardless of whether it resides in primary or auxiliary systems, and that vendor risk management must include continuous monitoring, not just point-in-time assessments.

Tactical Insight

Immediate actions

  • Audit all third-party platforms that store or process sensitive client data and validate their access controls immediately.
  • Enforce least-privilege access policies on support ticketing systems, ensuring IT personnel can only access data relevant to their role.
  • Require multi-factor authentication (MFA) for all third-party support platforms handling regulated or sensitive data.

Long-term improvements

  • Establish a formal Third-Party Risk Management (TPRM) program that includes contractual security requirements, regular audits, and penetration testing for all vendors handling sensitive data.
  • Classify and tag sensitive data (e.g., tax documents) so automated controls can restrict its storage within unauthorized or unreviewed systems.
  • Implement data minimization practices to ensure support systems only receive the minimum data necessary to resolve tickets.

Detection measures

  • Deploy continuous monitoring and anomaly detection on all vendor-managed systems that interact with client data.
  • Set up alerting for unusual data access patterns, bulk downloads, or privilege escalation within third-party platforms.
  • Mandate that vendors provide real-time security event logs to your SIEM so your team can detect breaches independently of vendor disclosure timelines.