Ernst & Young Discloses Data Breach After Third-Party Support System Compromised

Ernst & Young (EY) has disclosed a data breach affecting some of its customers after attackers compromised a third-party support ticket system used by the firm’s IT personnel. The accounting and consulting giant is notifying affected individuals whose personal information may have been exposed.

The breach involved unauthorized access to EY’s internal support infrastructure, which is managed by an external vendor. Attackers were able to access support tickets containing personal data of some EY clients. The company stated that the breach was discovered during routine security monitoring and that immediate steps were taken to contain the incident.

EY has not disclosed the total number of affected individuals or the specific types of data that were compromised. However, support ticket systems often contain names, contact information, and details about client engagements that could include sensitive business information. The firm has engaged cybersecurity experts to investigate the incident and is working with law enforcement.

Third-party vendor compromises have become an increasingly common attack vector in 2026. Attackers target the interconnected nature of enterprise IT environments, seeking to breach a single vendor and then pivot to multiple downstream clients. The EY incident underscores the importance of supply chain security for professional services firms that handle sensitive client data.

This article was adapted from Bleeping Computer. Read the original here.