ProBackend
access management iam security
2 hours ago4 min read

Security & Compliance Analyst: Why EY’s Third-Party Support Hack Is a Wake-Up Call

Ernst & Young's breach through a third-party support ticket system exposes systemic gaps in how professional services firms manage vendor risk — a critical failure for a firm that audits others.

The Cloud Security Incident Response Playbook Angle

Here's where this incident gets interesting from a security & compliance perspective. EY is one of the world's four largest auditing and professional services providers, offering auditing, tax, consulting, and transaction advisory services in more than 150 countries. They're the firm that audits other firms. They're the ones who tell you how to do things right.

And they got hit through a third-party support ticket system. Not through a sophisticated APT campaign targeting their audit practice. Not through a zero-day in their core systems. Through the IT help desk.

This is exactly why your cloud security incident response playbook needs to account for third-party support systems. Most organizations focus their security controls on customer-facing applications, core databases, and remote access infrastructure. The support ticket system? It's treated as internal tooling — low priority, minimal monitoring, often running on legacy platforms with outdated patches.

But support ticket systems are goldmines for threat actors. They contain:

  • Internal network diagrams and infrastructure details
  • Password reset requests that reveal security questions and answers
  • Documents uploaded by employees for troubleshooting — which may include sensitive business data
  • Access to internal systems if the support platform integrates with your identity provider
  • Historical context about security incidents and remediation efforts

The BleepingComputer comments section had some speculation that this might involve ServiceNow, given EY's partnership with the platform. One commenter noted: "My two cents would be that it was their internal ticket system from ServiceNow (They are a partner and customer). After reading the notification sample it gives you a few hints. Third party service management solution, internal IT supporting staff. Probably got in through breached AD."

Whether it's ServiceNow, Freshservice, Zendesk, or something else, the lesson is the same: your support ticket system is a security boundary, and it needs to be treated like one.

Related: Cloud Security Incident Response Playbook

What This Means for Affected Clients

EY is offering 24 months of identity monitoring and restoration service through Experian, with enrollment urged by October 31, 2026. That's a reasonable response, though it doesn't undo the fact that personal and financial data may have been exposed.

Here's what affected clients should do, regardless of whether they receive a notification:

Monitor your tax accounts. If you're an EY client, check your IRS account (if you're in the U.S.) and your state tax agency portals for any unusual activity. File your taxes early if you haven't already, and consider placing a fraud alert or credit freeze.

Watch for phishing. Breach notifications often trigger follow-up phishing campaigns. If you get an email claiming to be from EY or Experian about your breach, verify it through official channels before clicking anything.

Secure your accounts. If you have an EY client portal, change your password and enable multi-factor authentication if you haven't already. The same goes for any account where you've used the same password.

Document everything. Keep copies of the breach notification, any correspondence with EY, and records of steps you've taken to protect yourself. If your data is misused down the line, you'll need that paper trail.

The October 31, 2026 enrollment deadline gives you time, but don't let it slip your mind. Identity monitoring services are most useful when they catch problems early, not six months after the fact.

The Bigger Picture: Third-Party Risk in Professional Services

This incident fits into a broader pattern of third-party breaches hitting professional services firms. LastPass suffered CRM data exposure following a third-party OAuth incident. SoFi confirmed a data breach at its Hong Kong subsidiary involving vendor database compromise. Oxford University's CareerConnect platform breach exposed third-party risks in higher education.

The common thread? Organizations are trusting critical data to platforms they don't fully control, with security postures that may not match the sensitivity of the information flowing through them.

For EY specifically, this is particularly damaging because their entire business model is built on trust. Clients hand them their most sensitive financial data, expecting that the firm has rigorous security controls in place. When one of the world's largest auditing firms gets hit through a support ticket system, it undermines that trust in ways that go beyond the immediate incident.

The security & compliance community needs to take note: if EY can't secure its IT support system, what does that say about the firms they're auditing? It's not a fair question to ask, but it's one that clients will be asking.

As for EY, the path forward involves a thorough review of third-party risk management practices, enhanced monitoring of support ticket systems, and likely some uncomfortable conversations with vendors about security requirements. The 24-month identity monitoring offering is table stakes — the real test will be whether they can demonstrate meaningful improvements in how they protect client data going forward.

Related: Security & Compliance Center: Office 365 Best Practices

More blogs