{"id":27401069,"date":"2026-07-20T19:22:29","date_gmt":"2026-07-20T19:22:29","guid":{"rendered":"https:\/\/cybrt.sa\/?p=27401069"},"modified":"2026-08-23T12:06:13","modified_gmt":"2026-08-23T12:06:13","slug":"do-you-perform-third-party-risk-managementthe-ey-breach","status":"publish","type":"post","link":"https:\/\/cybrt.nukhtastudio.com\/ar\/do-you-perform-third-party-risk-managementthe-ey-breach\/","title":{"rendered":"Do You Perform Third Party Risk Management? (The EY Breach)"},"content":{"rendered":"<h2>Do You Perform Third Party Risk Management? (The EY Breach)<\/h2>\n<h4>What Happened<\/h4>\n<p>Ernst &amp; Young LLP (EY), one of the world&#8217;s largest professional services firms, has confirmed that client tax data was exposed after attackers breached a third party IT service management platform used by its tax practice. EY relies on this vendor hosted platform to help its internal IT staff support teams working on tax related client engagements, and support tickets logged there routinely carried attachments containing sensitive client information.EY detected anomalous activity on April 23, 2026, and immediately triggered incident response. The subsequent investigation conducted with an external cybersecurity firm, found that unauthorized access had actually begun on March 28, 2026 and continued until April 12, 2026, meaning attackers had roughly two weeks inside the platform before the intrusion was even noticed. During that window, documents belonging to numerous clients were downloaded, including personal and financial data used for tax preparation and in some cases, information tied to individuals&#8217; investment holdings.<br \/>\nEY filed formal breach notifications with the California Attorney General on July 15, 2026, and began mailing notice letters to affected individuals on July 13, 2026. The firm has stated it found no evidence of misuse so far, has secured the affected systems, and has notified federal law enforcement.<\/p>\n<h4>Why This Matters: The Vendor Is the Perimeter<\/h4>\n<p>EY&#8217;s own network was never compromised. The weak link was a third-party support platform.A category of tool almost every large organization uses for IT ticketing, customer support, or document sharing. This is the pattern behind a growing share of 2026&#8217;s major breaches: attackers are increasingly bypassing hardened corporate networks and going after the vendors, contractors, and SaaS platforms that sit just outside them but still hold sensitive data.<br \/>\nThree factors made this breach worse than it needed to be:<br \/>\n\u2022 Sensitive data drifted into a low scrutiny system. Support tickets became an unofficial repository for tax<br \/>\ndocuments, because it was convenient not because anyone decided it should be.<br \/>\n\u2022 Detection lagged compromise by nearly a month. Almost three weeks passed between initial access and the first sign of anomalous activity, giving attackers a wide window to operate undetected.<br \/>\n\u2022 Vendor risk wasn&#8217;t treated as organizational risk. A breach inside a vendor&#8217;s platform became a breach of EY&#8217;s clients&#8217; data, with EY facing the regulatory and reputational consequences.<\/p>\n<h4>Lessons for Every Organization<\/h4>\n<p>\u2022 Inventory every third party that can touch, store, or transmit sensitive data not just the ones with formal dataprocessing agreements.<br \/>\n\u2022 Classify vendors by data sensitivity and access level, and apply proportionally stronger due diligence and<br \/>\nmonitoring to the highest risk ones.<br \/>\n\u2022 Restrict what sensitive data is allowed to enter vendor platforms in the first place,support tickets and shared drives should not double as document archives.<br \/>\n\u2022 Require vendors to demonstrate real controls: MFA, encryption, logging, and incident response commitments and verify them, don&#8217;t just take their word for it.<br \/>\n\u2022 Shorten detection time with continuous monitoring of vendor connected systems, not just annual questionnaires or one time audits.<br \/>\n\u2022 Build a joint incident response plan with critical vendors before an incident happens, including clear notification timelines.<\/p>\n<h4>How Cybrt Helps<\/h4>\n<p>This is precisely the gap third party risk management programs exist to close. Cybrt helps organizations move from reactive vendor questionnaires to continuous, evidence based oversight, vendor risk assessments and tiering, ongoing monitoring for vendor side exposure, and incident response planning that accounts for the vendors sitting inside your data flow. The goal is simple: know where your sensitive data actually lives, and don&#8217;t find out through a breach notification letter.<strong>Explore our <a href=\"https:\/\/cybrt.nukhtastudio.com\/ar\/%d8%a7%d9%84%d8%ae%d8%af%d9%85%d8%a7%d8%aa\/\">\u0627\u0644\u062e\u062f\u0645\u0627\u062a<\/a><\/strong> to see how we help organizations build continuous, evidence based vendor risk programs.<\/p>\n<h4>The Takeaway<\/h4>\n<p>Security teams cannot fully control a vendor&#8217;s environment, but they can control what data reaches it, how quickly they&#8217;d notice if something went wrong, and how prepared they are to respond. The EY incident is a reminder that trust in a vendor is not a substitute for visibility into one.<\/p>","protected":false},"excerpt":{"rendered":"<p>Do You Perform Third Party Risk Management? (The EY Breach) What Happened Ernst &amp; Young LLP (EY), one of the world&#8217;s largest professional services firms, has confirmed that client tax data was exposed after attackers breached a third party IT service management platform used by its tax practice. EY relies on this vendor hosted platform [&hellip;]<\/p>\n","protected":false},"author":8,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[32],"tags":[],"dipi_cpt_category":[],"class_list":["post-27401069","post","type-post","status-publish","format-standard","hentry","category-supply-chain-risk-management"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.8 (Yoast SEO v28.5) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Do You Perform Third Party Risk Management? (The EY Breach) - CYBRT<\/title>\n<meta name=\"robots\" content=\"noindex, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<meta property=\"og:locale\" content=\"ar_AR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Do You Perform Third Party Risk Management? (The EY Breach)\" \/>\n<meta property=\"og:description\" content=\"Do You Perform Third Party Risk Management? (The EY Breach) What Happened Ernst &amp; Young LLP (EY), one of the world&#8217;s largest professional services firms, has confirmed that client tax data was exposed after attackers breached a third party IT service management platform used by its tax practice. EY relies on this vendor hosted platform [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/cybrt.nukhtastudio.com\/ar\/do-you-perform-third-party-risk-managementthe-ey-breach\/\" \/>\n<meta property=\"og:site_name\" content=\"CYBRT\" \/>\n<meta property=\"article:published_time\" content=\"2026-07-20T19:22:29+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-23T12:06:13+00:00\" \/>\n<meta name=\"author\" content=\"Saad Khan\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u0643\u064f\u062a\u0628 \u0628\u0648\u0627\u0633\u0637\u0629\" \/>\n\t<meta name=\"twitter:data1\" content=\"Saad Khan\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u0648\u0642\u062a \u0627\u0644\u0642\u0631\u0627\u0621\u0629 \u0627\u0644\u0645\u064f\u0642\u062f\u0651\u0631\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 \u062f\u0642\u0627\u0626\u0642\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/cybrt.nukhtastudio.com\\\/do-you-perform-third-party-risk-managementthe-ey-breach\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/cybrt.nukhtastudio.com\\\/do-you-perform-third-party-risk-managementthe-ey-breach\\\/\"},\"author\":{\"name\":\"Saad Khan\",\"@id\":\"https:\\\/\\\/cybrt.nukhtastudio.com\\\/#\\\/schema\\\/person\\\/e4071b81f2b3f32e77c95ac405103dd9\"},\"headline\":\"Do You Perform Third Party Risk Management? (The EY Breach)\",\"datePublished\":\"2026-07-20T19:22:29+00:00\",\"dateModified\":\"2026-08-23T12:06:13+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/cybrt.nukhtastudio.com\\\/do-you-perform-third-party-risk-managementthe-ey-breach\\\/\"},\"wordCount\":665,\"commentCount\":0,\"articleSection\":[\"Supply Chain Risk Management\"],\"inLanguage\":\"ar\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/cybrt.nukhtastudio.com\\\/do-you-perform-third-party-risk-managementthe-ey-breach\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/cybrt.nukhtastudio.com\\\/do-you-perform-third-party-risk-managementthe-ey-breach\\\/\",\"url\":\"https:\\\/\\\/cybrt.nukhtastudio.com\\\/do-you-perform-third-party-risk-managementthe-ey-breach\\\/\",\"name\":\"Do You Perform Third Party Risk Management? (The EY Breach) - CYBRT\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/cybrt.nukhtastudio.com\\\/#website\"},\"datePublished\":\"2026-07-20T19:22:29+00:00\",\"dateModified\":\"2026-08-23T12:06:13+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/cybrt.nukhtastudio.com\\\/#\\\/schema\\\/person\\\/e4071b81f2b3f32e77c95ac405103dd9\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/cybrt.nukhtastudio.com\\\/do-you-perform-third-party-risk-managementthe-ey-breach\\\/#breadcrumb\"},\"inLanguage\":\"ar\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/cybrt.nukhtastudio.com\\\/do-you-perform-third-party-risk-managementthe-ey-breach\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/cybrt.nukhtastudio.com\\\/do-you-perform-third-party-risk-managementthe-ey-breach\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/cybrt.nukhtastudio.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Do You Perform Third Party Risk Management? (The EY Breach)\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/cybrt.nukhtastudio.com\\\/#website\",\"url\":\"https:\\\/\\\/cybrt.nukhtastudio.com\\\/\",\"name\":\"CYBRT\",\"description\":\"Cybersecurity Excellence\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/cybrt.nukhtastudio.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"ar\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/cybrt.nukhtastudio.com\\\/#\\\/schema\\\/person\\\/e4071b81f2b3f32e77c95ac405103dd9\",\"name\":\"Saad Khan\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"ar\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f6269105fe4f0a1964d9a02d99c01e1ae28221b6e3952220afced3a69ec37deb?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f6269105fe4f0a1964d9a02d99c01e1ae28221b6e3952220afced3a69ec37deb?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f6269105fe4f0a1964d9a02d99c01e1ae28221b6e3952220afced3a69ec37deb?s=96&d=mm&r=g\",\"caption\":\"Saad Khan\"},\"url\":\"https:\\\/\\\/cybrt.nukhtastudio.com\\\/ar\\\/author\\\/saad\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Do You Perform Third Party Risk Management? (The EY Breach) - CYBRT","robots":{"index":"noindex","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"og_locale":"ar_AR","og_type":"article","og_title":"Do You Perform Third Party Risk Management? (The EY Breach)","og_description":"Do You Perform Third Party Risk Management? (The EY Breach) What Happened Ernst &amp; Young LLP (EY), one of the world&#8217;s largest professional services firms, has confirmed that client tax data was exposed after attackers breached a third party IT service management platform used by its tax practice. EY relies on this vendor hosted platform [&hellip;]","og_url":"https:\/\/cybrt.nukhtastudio.com\/ar\/do-you-perform-third-party-risk-managementthe-ey-breach\/","og_site_name":"CYBRT","article_published_time":"2026-07-20T19:22:29+00:00","article_modified_time":"2026-08-23T12:06:13+00:00","author":"Saad Khan","twitter_card":"summary_large_image","twitter_misc":{"\u0643\u064f\u062a\u0628 \u0628\u0648\u0627\u0633\u0637\u0629":"Saad Khan","\u0648\u0642\u062a \u0627\u0644\u0642\u0631\u0627\u0621\u0629 \u0627\u0644\u0645\u064f\u0642\u062f\u0651\u0631":"3 \u062f\u0642\u0627\u0626\u0642"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/cybrt.nukhtastudio.com\/do-you-perform-third-party-risk-managementthe-ey-breach\/#article","isPartOf":{"@id":"https:\/\/cybrt.nukhtastudio.com\/do-you-perform-third-party-risk-managementthe-ey-breach\/"},"author":{"name":"Saad Khan","@id":"https:\/\/cybrt.nukhtastudio.com\/#\/schema\/person\/e4071b81f2b3f32e77c95ac405103dd9"},"headline":"Do You Perform Third Party Risk Management? (The EY Breach)","datePublished":"2026-07-20T19:22:29+00:00","dateModified":"2026-08-23T12:06:13+00:00","mainEntityOfPage":{"@id":"https:\/\/cybrt.nukhtastudio.com\/do-you-perform-third-party-risk-managementthe-ey-breach\/"},"wordCount":665,"commentCount":0,"articleSection":["Supply Chain Risk Management"],"inLanguage":"ar","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/cybrt.nukhtastudio.com\/do-you-perform-third-party-risk-managementthe-ey-breach\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/cybrt.nukhtastudio.com\/do-you-perform-third-party-risk-managementthe-ey-breach\/","url":"https:\/\/cybrt.nukhtastudio.com\/do-you-perform-third-party-risk-managementthe-ey-breach\/","name":"Do You Perform Third Party Risk Management? (The EY Breach) - CYBRT","isPartOf":{"@id":"https:\/\/cybrt.nukhtastudio.com\/#website"},"datePublished":"2026-07-20T19:22:29+00:00","dateModified":"2026-08-23T12:06:13+00:00","author":{"@id":"https:\/\/cybrt.nukhtastudio.com\/#\/schema\/person\/e4071b81f2b3f32e77c95ac405103dd9"},"breadcrumb":{"@id":"https:\/\/cybrt.nukhtastudio.com\/do-you-perform-third-party-risk-managementthe-ey-breach\/#breadcrumb"},"inLanguage":"ar","potentialAction":[{"@type":"ReadAction","target":["https:\/\/cybrt.nukhtastudio.com\/do-you-perform-third-party-risk-managementthe-ey-breach\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/cybrt.nukhtastudio.com\/do-you-perform-third-party-risk-managementthe-ey-breach\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/cybrt.nukhtastudio.com\/"},{"@type":"ListItem","position":2,"name":"Do You Perform Third Party Risk Management? (The EY Breach)"}]},{"@type":"WebSite","@id":"https:\/\/cybrt.nukhtastudio.com\/#website","url":"https:\/\/cybrt.nukhtastudio.com\/","name":"CYBRT","description":"\u0627\u0644\u062a\u0645\u064a\u0632 \u0641\u064a \u0627\u0644\u0623\u0645\u0646 \u0627\u0644\u0633\u064a\u0628\u0631\u0627\u0646\u064a","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/cybrt.nukhtastudio.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"ar"},{"@type":"Person","@id":"https:\/\/cybrt.nukhtastudio.com\/#\/schema\/person\/e4071b81f2b3f32e77c95ac405103dd9","name":"Saad Khan","image":{"@type":"ImageObject","inLanguage":"ar","@id":"https:\/\/secure.gravatar.com\/avatar\/f6269105fe4f0a1964d9a02d99c01e1ae28221b6e3952220afced3a69ec37deb?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f6269105fe4f0a1964d9a02d99c01e1ae28221b6e3952220afced3a69ec37deb?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f6269105fe4f0a1964d9a02d99c01e1ae28221b6e3952220afced3a69ec37deb?s=96&d=mm&r=g","caption":"Saad Khan"},"url":"https:\/\/cybrt.nukhtastudio.com\/ar\/author\/saad\/"}]}},"_links":{"self":[{"href":"https:\/\/cybrt.nukhtastudio.com\/ar\/wp-json\/wp\/v2\/posts\/27401069","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cybrt.nukhtastudio.com\/ar\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybrt.nukhtastudio.com\/ar\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cybrt.nukhtastudio.com\/ar\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/cybrt.nukhtastudio.com\/ar\/wp-json\/wp\/v2\/comments?post=27401069"}],"version-history":[{"count":4,"href":"https:\/\/cybrt.nukhtastudio.com\/ar\/wp-json\/wp\/v2\/posts\/27401069\/revisions"}],"predecessor-version":[{"id":27401074,"href":"https:\/\/cybrt.nukhtastudio.com\/ar\/wp-json\/wp\/v2\/posts\/27401069\/revisions\/27401074"}],"wp:attachment":[{"href":"https:\/\/cybrt.nukhtastudio.com\/ar\/wp-json\/wp\/v2\/media?parent=27401069"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybrt.nukhtastudio.com\/ar\/wp-json\/wp\/v2\/categories?post=27401069"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybrt.nukhtastudio.com\/ar\/wp-json\/wp\/v2\/tags?post=27401069"},{"taxonomy":"dipi_cpt_category","embeddable":true,"href":"https:\/\/cybrt.nukhtastudio.com\/ar\/wp-json\/wp\/v2\/dipi_cpt_category?post=27401069"}],"curies":[{"name":"\u062f\u0628\u0644\u064a\u0648 \u0628\u064a","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}