Global professional services firm Ernst & Young (EY) disclosed a cybersecurity incident after attackers compromised a third party IT support platform used by the company, potentially exposing sensitive client tax documents and employee information. According to EY, the breach was limited to the external support environment and did not involve unauthorized access to the firm’s core internal network. However, the compromised platform contained support case information and documents submitted by clients and employees, prompting the company to launch an investigation and notify affected individuals. While the full scope of the incident remains under investigation, EY stated that it is working with cybersecurity specialists and relevant authorities to assess the impact and strengthen security controls.
The incident highlights the growing risks associated with third party service providers, which continue to serve as attractive targets for threat actors seeking indirect access to large enterprises and their customers. Professional services firms such as EY maintain extensive repositories of financial, tax, legal, and corporate information, making them particularly valuable targets for cybercriminals. Even when a compromise is confined to an external vendor, attackers may still gain access to sensitive documentation that can facilitate fraud, identity theft, business email compromise (BEC), or follow on attacks against clients.
The breach serves as another reminder that organizations must extend cybersecurity oversight beyond their own environments to include suppliers, managed service providers, and other third party platforms that process sensitive information. Effective third party risk management should include regular security assessments, contractual security requirements, least privilege access controls, continuous monitoring of vendor activity, and incident response procedures that account for supply chain compromises. As organizations become increasingly reliant on external technology providers, securing the broader digital ecosystem remains a critical component of enterprise cyber resilience.