Do You Perform Third Party Risk Management? (The EY Breach)
What Happened
Ernst & Young LLP (EY), one of the world’s largest professional services firms, has confirmed that client tax data was exposed after attackers breached a third party IT service management platform used by its tax practice. EY relies on this vendor hosted platform to help its internal IT staff support teams working on tax related client engagements, and support tickets logged there routinely carried attachments containing sensitive client information.EY detected anomalous activity on April 23, 2026, and immediately triggered incident response. The subsequent investigation conducted with an external cybersecurity firm, found that unauthorized access had actually begun on March 28, 2026 and continued until April 12, 2026, meaning attackers had roughly two weeks inside the platform before the intrusion was even noticed. During that window, documents belonging to numerous clients were downloaded, including personal and financial data used for tax preparation and in some cases, information tied to individuals’ investment holdings.
EY filed formal breach notifications with the California Attorney General on July 15, 2026, and began mailing notice letters to affected individuals on July 13, 2026. The firm has stated it found no evidence of misuse so far, has secured the affected systems, and has notified federal law enforcement.
Why This Matters: The Vendor Is the Perimeter
EY’s own network was never compromised. The weak link was a third-party support platform.A category of tool almost every large organization uses for IT ticketing, customer support, or document sharing. This is the pattern behind a growing share of 2026’s major breaches: attackers are increasingly bypassing hardened corporate networks and going after the vendors, contractors, and SaaS platforms that sit just outside them but still hold sensitive data.
Three factors made this breach worse than it needed to be:
• Sensitive data drifted into a low scrutiny system. Support tickets became an unofficial repository for tax
documents, because it was convenient not because anyone decided it should be.
• Detection lagged compromise by nearly a month. Almost three weeks passed between initial access and the first sign of anomalous activity, giving attackers a wide window to operate undetected.
• Vendor risk wasn’t treated as organizational risk. A breach inside a vendor’s platform became a breach of EY’s clients’ data, with EY facing the regulatory and reputational consequences.
Lessons for Every Organization
• Inventory every third party that can touch, store, or transmit sensitive data not just the ones with formal dataprocessing agreements.
• Classify vendors by data sensitivity and access level, and apply proportionally stronger due diligence and
monitoring to the highest risk ones.
• Restrict what sensitive data is allowed to enter vendor platforms in the first place,support tickets and shared drives should not double as document archives.
• Require vendors to demonstrate real controls: MFA, encryption, logging, and incident response commitments and verify them, don’t just take their word for it.
• Shorten detection time with continuous monitoring of vendor connected systems, not just annual questionnaires or one time audits.
• Build a joint incident response plan with critical vendors before an incident happens, including clear notification timelines.
How Cybrt Helps
This is precisely the gap third party risk management programs exist to close. Cybrt helps organizations move from reactive vendor questionnaires to continuous, evidence based oversight, vendor risk assessments and tiering, ongoing monitoring for vendor side exposure, and incident response planning that accounts for the vendors sitting inside your data flow. The goal is simple: know where your sensitive data actually lives, and don’t find out through a breach notification letter.Explore our الخدمات to see how we help organizations build continuous, evidence based vendor risk programs.
The Takeaway
Security teams cannot fully control a vendor’s environment, but they can control what data reaches it, how quickly they’d notice if something went wrong, and how prepared they are to respond. The EY incident is a reminder that trust in a vendor is not a substitute for visibility into one.
