CuraSec

Act archived

Ernst & Young discloses data breach via support system hack

2026-07-18 11:51 UTC · BleepingComputer · read the source ↗ #data-breach#third-party-risk#vendor-compromise
  • Engineer — Skip
  • SOC/IR — Learn: The breach originated through a third-party support ticketing system, illustrating a lateral entry path worth reviewing in your own vendor-managed tool integrations — no IOCs or TTPs published to act on yet.
  • Leader — Act: If EY is a vendor or auditor your organization uses, confirm whether your data was in scope and request EY’s incident report; brief leadership now, before this becomes a customer or auditor question.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.