Decoding the world of cybersecurity

Support platform breach exposes EY client documents

Documents were downloaded from a third-party support platform used by EY, showing how service-management systems can accumulate sensitive client information beyond their original operational purpose.

Support platform breach exposes EY client documents
Summary
  • EY says an intruder accessed a third-party IT service-management platform between 28 March and 12 April.
  • Downloaded documents may have contained client tax, financial, and personal information.
  • Support environments require controlled retention, restricted administration, secure file transfer, and clear supplier incident obligations.

An intruder downloaded documents from a third-party support platform used by EY for tax-related services, exposing information that may include client financial, tax, and personal records.

EY said it detected unusual activity on 23 April and determined that an unauthorised party had accessed the platform between 28 March and 12 April. The company removed the access, secured the environment, and began reviewing the affected documents.

The material varied according to the support request and may have included information used in tax filings. EY has not publicly identified the platform provider, the number of clients affected, or the geographic distribution of the records.

The company said it had not identified evidence that the information had been misused or that particular individuals had been targeted at the time notices were issued. Downloaded data can retain value for fraud, impersonation, social engineering, and attempts to access other professional services even where immediate misuse is not visible.

Support platforms are often procured as workflow tools, although their contents can resemble an unstructured archive of sensitive business operations. Employees and clients may attach identity documents, financial statements, screenshots, log files, configuration details, or correspondence when trying to resolve a case quickly.

Information entered for one support request can remain after the ticket closes, while copies may exist in email notifications, backups, analytics tools, and supplier systems. Retention controls applied to the original business record may not automatically remove these secondary copies.

Support records as a shared data store

Access to ticketing systems often extends across internal teams, service providers, specialists, and subcontractors. Administrators may be able to search across several customers or business units, giving one compromised account access to records accumulated from otherwise separate engagements.

Organisations should include support platforms within their regulated-data estate rather than treating them as peripheral administrative services. Classification, data-loss prevention, audit, retention, and privileged-access controls need to operate regardless of whether the platform is hosted internally or by a supplier.

Files containing identity, financial, or legal material can be moved through secure transfer services rather than stored directly in general case notes. Automated checks can also identify passwords, access tokens, identity documents, and payment information before they become embedded in ticket histories.

Service teams need practical alternatives so that secure handling does not obstruct the work. Where the approved process is slow or difficult, staff are more likely to paste credentials into a ticket, attach a complete dataset, or transfer material through email.

Supplier assessments should establish where support data is stored, which subcontractors can reach it, how administrators authenticate, and how quickly the provider can produce complete logs. Contracts need to define deletion of closed-ticket material, return of customer data, evidence preservation, incident notification, and support for regulatory investigation.

The disclosure may produce notification duties in several jurisdictions according to the individuals and information involved. Professional-services companies often process client records across national boundaries, and each downloaded document may need to be classified before the relevant obligations can be determined.

The confirmed incident concerns the third-party support environment and documents held within it. EY has not disclosed evidence that its wider network or client production systems were compromised.

That boundary still covers a valuable concentration of information. Support systems sit between clients, internal specialists, and technology suppliers, preserving records of problems, configurations, and business activity that may be more revealing than a structured database.

Reducing that exposure requires limits on what support platforms are allowed to become. Sensitive attachments should have defined retention periods, administrative access should remain narrow and traceable, and suppliers should be able to demonstrate how customer records are separated and removed.

×