EY Breached Through Third-Party Support Ticket System
What Happened
Client tax documents and financial data downloaded from a third-party IT support ticket system. The platform stored sensitive information from tax-related support requests. EY's own systems stayed intact. The breach happened at the vendor.
How They Got In
An unauthorized third party accessed the support platform between March 28 and April 12, 2026. EY detected anomalous activity on April 23. That was 15 days after the breach happened. By then, documents were already gone. No details on how attackers got initial access.
The Pattern
48% of breaches now involve a third party. EY trusted a support ticket system with client tax data. The vendor didn't have visibility into abnormal access. EY didn't either until regulators asked questions.
What FrontierZero Catches
A support platform suddenly accessed from unusual IP ranges or geographic locations. Bulk downloads that spike above normal patterns. Service account logins outside business hours. Contractor credentials without MFA being used to pull sensitive data.
The Gap
You approve a support system vendor. They hold sensitive client data. You assume they're monitoring for breaches. They're not. Attackers stay quiet for two weeks, pull what they need, and leave. You find out a month later.
What You Need
Real-time visibility into every third-party platform touching your client data. Know what normal access looks like on support systems, APIs, and integrations. Catch bulk downloads. Catch logins from new locations. Catch when permissions get abused. Before data walks out.
Get your External Connections Report. See which third-party systems hold your sensitive data and whether you can actually see suspicious behavior.