[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fYbR9wmpRyu-tYO2GY5xQGEgGpth7zV9Yq6cV5dx5EHs":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":25,"created_at":26,"published_at":27,"article":28,"tags":32,"podcasts":51},"bcc467d6-af8c-40f9-b631-3ca84b41a8c9","shinyhunters-breach-ey-via-third-party-ticket-system","a57f5ef4-30b2-442f-928d-5c50bc41b428","ShinyHunters Breach EY via Third-Party Ticket System","The Ernst & Young breach illustrates how a trusted third-party IT support vendor can become the weakest link in an enterprise security chain — attackers compromised a ticket management system to harvest credentials and pivot into EY's core development and cloud environments (Jira, GitHub, Azure). This matters because even the most sophisticated organizations inherit the security posture of every vendor they connect to, meaning a single under-secured third party can expose highly sensitive client financial and tax data. The exfiltration of support ticket contents is particularly damaging since such tickets routinely contain credentials, configuration details, and client PII shared during troubleshooting. Without rigorous third-party security assessments and least-privilege access enforcement, supply-chain entry points will continue to be attractive and effective attack vectors.","**Immediate actions:**\n- Audit and revoke all third-party vendor credentials with access to internal systems (Jira, GitHub, Azure) and rotate any potentially compromised secrets immediately.\n- Enforce multi-factor authentication (MFA) on every third-party integration point and privileged identity accessing internal platforms.\n- Review and sanitize support ticket workflows to ensure sensitive credentials and client data are never stored in plain text within ticket bodies.\n\n**Long-term improvements:**\n- Establish a formal Third-Party Risk Management (TPRM) program requiring vendors to meet defined security baselines before integration is approved.\n- Apply the principle of least privilege to all vendor and third-party service accounts, scoping access only to the specific resources required for their function.\n- Implement data classification and tokenization controls so that client financial information is masked or redacted before appearing in support tooling.\n\n**Detection measures:**\n- Deploy CASB (Cloud Access Security Broker) and UEBA solutions to detect anomalous access patterns originating from third-party accounts across cloud and DevOps environments.\n- Centralize logging from Jira, GitHub, and Azure into a SIEM and configure alerts for bulk data exports or privilege escalation events initiated by service accounts.\n- Conduct regular purple-team exercises simulating supply-chain compromise scenarios to validate detection and response capabilities.",[12,13,14,15,16,17,18,19,20,21,22,23,24],"CIS Control 15 – Service Provider Management","CIS Control 6 – Access Control Management","CIS Control 3 – Data Protection","NIST SP 800-161 – Supply Chain Risk Management","NIST AC-2 – Account Management","NIST AC-6 – Least Privilege","NIST IR-6 – Incident Reporting","NIST SR-6 – Supplier Assessments and Reviews","ISO 27001 Annex A.15 – Supplier Relationships","GDPR Article 28 – Processor Obligations","GDPR Article 32 – Security of Processing","GDPR Article 33 – Notification of Personal Data Breach","ITIL 4 – Supplier Management Practice","published","2026-07-27T16:20:41.72741+00:00","2026-07-27T16:20:41.646+00:00",{"id":7,"url":29,"slug":30,"title":31},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fernst-and-young-data-breach-claimed-by-shinyhunters-extortion-gang\u002F","ernst-young-data-breach-claimed-by-shinyhunters-extortion-gang-c9d9f9","Ernst & Young data breach claimed by ShinyHunters extortion gang",[33,39,45],{"id":34,"name":35,"slug":36,"description":37,"color":38},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":40,"name":41,"slug":42,"description":43,"color":44},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",{"id":46,"name":47,"slug":48,"description":49,"color":50},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]