Ernst & Young Reports Breach Through Third-Party Support System
Third-party support platforms remain a persistent weak point in enterprise security architectures.
What happened
Ernst & Young disclosed that attackers compromised a third-party support ticket system used by its IT staff. The accounting and consulting firm is notifying affected customers whose data may have been exposed through the breach.
The incident adds to a growing pattern of breaches originating from support and ticketing platforms. These systems often handle sensitive information exchanged during troubleshooting and customer service interactions.
The third-party challenge
Organizations face ongoing difficulty securing systems they do not directly control. Support platforms sit at the intersection of internal operations and external customers, making them attractive targets that contain valuable data from both sides.
Security teams evaluating support and ticketing tools should assess not just the vendor's security posture but also the data exposure if that system is compromised. Minimizing what flows through these channels reduces risk when breaches occur.