Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Showing posts with label EY. Show all posts

Ernst & Young Notifies Clients Following Third-Party Support Platform Data Breach

 

The company Ernst & Young (EY) has sent out notices to the affected clients about the data breach involving the third-party support ticket platform, which EY’s employees used, and therefore, potentially exposed documents with sensitive tax details to hackers. EY is one of the world’s largest accounting firms that is known to have faced a cybersecurity incident when the unauthorized party gained access to the third-party support ticket platform used by EY’s IT staff on March 28, 2026, and removed several documents from it, reported on April 23, 2026. 

A company statement noted, after reviewing the activity within its environment with the help of outside cybersecurity experts, that the threat actors accessed the EY environment between March 28, 2026, and April 12, 2026. As per the breach notification letter, the documents removed from the support platform could include personal information or financial information, as well as details provided to EY’s support teams during the process of submitting the tickets or in connection with the preparation of the clients’ tax returns. 

EY acknowledges that tax-related information may have been involved in the data security incident but chose not to identify what specific details were affected, as the breach notification letters also include placeholders for the affected customers’ personal information. The company also declined to indicate how many clients were affected by the breach or whether it was limited to the U.S., as there are other EY entities around the globe. EY announced that after detecting the issue, the company took measures to secure the affected systems by cutting down the unauthorized access, and notified the appropriate federal agencies. 

Furthermore, EY has found no evidence that the information from the breach had been deployed or that any particular individuals were the specific targets. Nevertheless, the firm offered its affected clients with credit monitoring and identity theft protection services for 24 months for free from Experian. The customers whose data was at risk were encouraged to sign up for the monitoring services by October 31, 2026. 

At the moment of the announcement, neither ransomware gangs nor data extortionists have claimed responsibility for the cyberattack, nor did any bad actors leak the data or sell it on the dark web. The attack involving the third-party support ticket platform yet again demonstrated the challenges organizations face regarding their ability to protect clients’ data and ensure that their vendors and partners do the same. 

Experts note that companies should invest in making sure their third-party vendors have reliable security practices in place, monitor their activity on a regular basis, and avoid storing any sensitive data on the platforms that can be accessed by numerous individuals, as in the case of EY’s tickets system, to mitigate the risks of supply chain breaches and data leakage incidents.

Cl0p Ransomware Targets Sony, EY, and PwC in MOVEit Transfer Cyberattack

 

The recent attack, which commenced earlier this month, has the potential to become one of the largest cyberattacks in history. Its victims include various entities from the public and private sectors in the United States, United Kingdom, and other countries.

Reports suggest that Cl0p, the cybercriminal group behind the attack, claims to possess data from prominent organizations like Sony, as well as leading accountancy firms EY and PwC. In a statement, Cl0p warned that it possesses approximately 120GB of data from PwC, which it may release if its demands are not met.

However, Cl0p denies having any data from government agencies, emphasizing that its focus lies solely on exploiting private companies for financial gain. The group clarifies on its blog that it receives numerous emails regarding government data but promptly deletes such information, as its motivations are primarily monetary and not political.

Typically, ransomware groups deny possessing sensitive government information, especially if they believe that holding such data would invite closer scrutiny from law enforcement agencies.

Notable organizations affected by the security vulnerability in MOVEit Transfer, a widely used secure file transfer system, include British Airways, the BBC, and Boots. These entities informed their staff that their data may have been compromised following a breach of payroll platform Zellis, which is used by all three companies.

Although Cl0p denies having any data from Zellis, an email exchange with the BBC reveals the group's claim that they do not possess the information and have notified Zellis about it. The group asserts its longstanding policy of truthfulness, stating that if they say they don't have certain data, they genuinely do not possess it.

The hackers allegedly set a deadline of 14 June for the affected companies to pay a ransom, or else their data would be exposed online. However, no information has been leaked thus far, raising the possibility that other cybercriminals may also be taking advantage of the MOVEit Transfer vulnerability. 

The software vendor, Progress Software, disclosed the glitch on 31 May, but no other hacker group has publicly claimed responsibility for stealing data through this exploit.