It Can't Go On Like This, Can it? It Can! EY Just Got Breached.
Their firewalls held. Their endpoint detection was solid. Their identity management locked down. Everything worked exactly as designed.
But on July 13, 2026, Ernst & Young sent notification letters to affected clients anyway. Millions of dollars in sensitive tax documents and financial records had been stolen.
Here's what should scare you: EY's network was never hacked.
That's the reality in 2026. You can get breached without your systems being touched.
An unnamed IT support platform vendor got compromised in March. For two weeks, an unauthorized actor downloaded tax documents, financial records, client information. EY didn't know it was happening. They couldn't see inside the vendor's system.
By April 23, when they finally detected it, the attacker had already been gone for 11 days with everything they needed.
The vendor breach became EY's breach. And EY's perfect security posture didn't matter.
The last three months have been rough in the Third-Party security scene
This isn't isolated. In just the last three months, we've seen a coordinated pattern of third-party breaches targeting major enterprises.
Deutsche Bank (July 2026): A German marketing and incentive platform used by Deutsche Bank's sales partners got compromised. Attackers exfiltrated employee credentials, password hashes, and internal records. Deutsche Bank's own infrastructure stayed untouched, but the attackers now had employee emails and credential data tied directly to the bank's ecosystem. Think about what you can do with a Deutsche Bank employee's email and password hash.
Lidl (June 2026): An IT service provider vendor got breached. Customer names, emails, phone numbers, dates of birth, customer numbers from across 12,000 stores in Germany, Belgium, and the Netherlands. That's millions of customers. Lidl's infrastructure clean. But their entire customer base's information flowed through a vendor they couldn't monitor.
EY (March-July 2026): Support platform vendor compromised. Tax documents and financial records stolen. These aren't just any files. These are the blueprints of client businesses, financial positions, tax strategies. Attackers now have everything needed to commit fraud or identity theft against EY's clients.
List of all the major third-party breaches this year.
Actually, it isn't rough now. It just keeps going
This wave didn't start in March. It started earlier.
Qantas (2025): A third-party API integration got breached. Customer loyalty program data exposed. Attackers got access to names, email addresses, loyalty numbers, dates of birth. That data immediately became usable for phishing campaigns targeting Qantas customers. Attackers knew exactly who to target and what to say. The breach affected them so bad that the executives lost $250k from their bonuses.
JLR (2025): Another vendor breach. Customer personal data exposed. Names, addresses, contact information. Again, it became the foundation for social engineering and credential stuffing attacks against JLR's customer base. Oh and this breach ended up costing a whopping 2 Billion (with a B) pounds.
Why You Should Care About It
According to Verizon's 2026 Data Breach Investigations Report, 48% of all breaches now involve a third party. That's up 60% from the previous year. This isn't a trend. This is a fundamental shift in how attackers operate.
They stopped targeting you directly. Your firewalls are too strong. Your detection is too good. Your security team is watching. Instead, they target your vendors because vendor security is weaker and the payoff is massive.
"What is the problem if they get tax data, not passwords?"
Attackers don't need your passwords or credit card numbers anymore. They need context.
Tax documents reveal financial positions and vulnerabilities. Customer email addresses enable hyper-targeted phishing campaigns. Names and dates of birth support identity theft and fraud. Employee credentials unlock internal systems. Loyalty data shows purchase patterns and high-value targets.
Each stolen data element is a building block for the next attack. And most of this data doesn't live in your network. It lives in your vendors' systems. Where you can't see it.
Why You're Currently Flying Blind
Here's what most IT and Security teams can't answer right now:
How many vendors actually have access to your sensitive data? Not the ones you remember. The actual number. Most teams are shocked when they count.
What specific data flows to each vendor? Where does it sit in their infrastructure? Who has access to it on their end? Can they download it? Export it?
What's happening inside those vendor systems right now? Is someone accessing your data at this moment? Has anyone downloaded files today? Are permissions changing?
If someone exfiltrated your customer database from a vendor's system tonight, when would you find out? EY found out 11 days later. Most companies find out weeks or months later. Some never find out unless the attacker publishes it.
EY had strong identity management. Solid endpoint detection. Good email security. A trained security team. Regular compliance audits. But they couldn't see inside their vendor's platform. They didn't have monitoring. They couldn't detect unusual activity. They found out too late because they were blind to what was happening outside their network.
How to See It Coming
Start with discovery. You need a complete, accurate inventory of every vendor, SaaS application, and service provider with access to any sensitive data. Not the ones you remember. Not the ones on your approved list. All of them. Most enterprises have 50-100+ SaaS vendors. Security teams typically know about 20.
Map your data flows. For each vendor, understand what specific data they receive. How often. Where it sits. How long it's retained. Who on their side has access. This is where most organizations discover they're exposing far more than they realized.
Establish what normal looks like. Normal activity inside your vendors' systems looks different than normal inside your network. You need baselines for login patterns, data access, permission usage, bulk downloads. Once you know what normal is, you can detect what isn't.
Monitor continuously. This can't be an annual audit. Attackers had two weeks inside EY's system before detection. You need real-time monitoring of access patterns, data flows, permission changes, unusual activity. That's where breaches hide before they become headlines.
How FrontierZero Solves This

We give you inside-out visibility into your entire external connection ecosystem.
In a single pane of glass, you can see all your external connections, their status, and more info. If one of the identities starts acting weird, you will know about it.
We automatically discover all your SaaS applications and vendors, not relying on security teams to remember what's connected. We monitor what's happening inside those systems 24/7, watching access patterns and data flows. We establish baseline behavior so anomalies stand out immediately. We alert you in real-time when something changes that shouldn't change.
This is what stops the EY story before the notification letters go out.
Get your supply chain glasses now
Map your external connections and see where your data is actually flowing.
Get your free external access report →
Then establish what normal looks like in those systems. Then monitor continuously.
Your vendor's security is your security now. And you need to see it.