vulnerability management

The latest EY breach - The helpdesk ticket that became a tax file archive

July 27, 2026
EY's breach came through a support ticket platform, not a database. Here's why shadow data in vendor tools is the real exposure gap, and how to close it.

EY just got breached through the one system nobody puts in their risk register.

Not the tax software. Not the client database. The support ticket platform.

Between March 28 and April 12, an unauthorized third party sat inside EY's IT service management tool and pulled documents that employees had attached to routine helpdesk tickets. Social Security numbers. Financial account data. Investment holdings. Actual tax filings. EY didn't catch it until April 23, eleven days after the access window had already closed.

Here's the part that should bother every security leader reading this. Nobody decided to store client tax records in a helpdesk system. It happened because that's what employees do when IT asks for a file to troubleshoot a problem: they attach the document sitting in front of them. Over months and years, a ticketing tool built for password resets and VPN issues quietly turns into a shadow archive of the most sensitive data a firm holds, and it never gets the access controls or monitoring that the "real" systems get.

This is EY's third vendor-side incident in under three years. MOVEit in 2023 through Cl0p. An exposed Azure backup in October 2025. Now an ITSM platform in 2026. Three different vendors, three different failure modes, one common thread: the breach never touched the primary system. It came in sideways, through infrastructure that supports the people who run the primary system.

Four states have been notified so far. The confirmed floor is 1,366 people. Given EY's client base spans Fortune 500 companies, private equity firms, and financial institutions across 150 countries, that number is a fraction of the real exposure.

So what do you do about this, beyond "patch your ticketing software"?

Start by asking a different question than most security teams ask. Not "is this system patched," but "what would an attacker find if they got in, and could they do anything with it." Traditional scanning tells you a vendor platform has a known CVE. It doesn't tell you that three years of employee-attached tax documents are sitting inside it, or that those documents are one authentication bypass away from a data breach notification letter.

That's where continuous, agentic exposure validation earns its keep. Instead of a point-in-time scan of your helpdesk tool, you get an AI-driven simulation that attempts the attacker's path: can it reach the ticketing platform, can it pull attachments, can it move from there into anything else. Run against every third-party and vendor-connected system, not just the ones on your asset inventory, because the whole problem with EY's breach is that nobody had that system on the inventory that mattered.

If you're a CISO or security engineering lead, do this exercise this week: pull up your IT service management platform and ask what's sitting in the attachment field of tickets closed in the last 24 months. You will find something you didn't expect. Every organization that has ever handed IT a document to fix a laptop problem has this exposure. Most just haven't looked yet.

For anyone who received a notification letter: freeze your credit at all bureaus, it costs nothing and blocks new accounts outright. Enroll in your local Identity Protection PIN program before filing season, since it stops fraudulent returns cold even if your SSN is already in someone else's hands. And watch for phishing that references your tax details. Generic spam filters won't catch an email that already knows your employer and your bank.

The lesson from this one isn't "get better at patching." It's that the systems securing your systems need the same scrutiny as the systems themselves.

Sagy Kratu

Sr. Product Marketing Manager

Subscribe for more

Get more infosec news and insights.
1000+ members

Turn security converstains into remediation actions