EY Probes Third-Party Support Platform After Customer Information Exposure
Ernst & Young (EY) is investigating a data security incident involving a third-party customer support platform after unauthorized actors gained access to support tickets containing client information.
The company said the breach was limited to a third-party ticketing system rather than EY's core internal network. Following the discovery, EY launched an investigation with external cybersecurity experts and began notifying affected customers.
Incident Involved Customer Support Records
According to EY, the attackers accessed support tickets stored by an external service provider used for customer assistance.
The exposed records may contain customer names, contact details, account-related information, and communications submitted during support requests. The exact type of information varies depending on the individual ticket, and the company continues to determine the full scope of the incident.
Core Corporate Systems Not Affected
EY stated that there is currently no evidence indicating that its primary corporate environment, client service platforms, or financial systems were compromised during the incident.
The investigation indicates that the unauthorized access was confined to the external support environment, although forensic analysis remains ongoing to confirm the extent of the exposure.
Investigation and Customer Notifications Underway
After identifying the incident, EY worked with the third-party provider to secure the affected environment, launched a forensic investigation, and began assessing which customers were impacted.
The company is contacting affected individuals where required and continues reviewing the compromised support records to determine what information may have been accessed.
Third-Party Risks Remain a Growing Security Challenge
The incident highlights the cybersecurity risks associated with third-party vendors that process customer information on behalf of large organizations.
Security experts recommend that organizations continuously assess supplier security controls, limit the amount of sensitive information stored in support platforms, implement multi-factor authentication, and regularly monitor third-party environments for suspicious activity.
Supply Chain Security Continues to Draw Attention
As businesses increasingly rely on external platforms for customer support, cloud services, and business operations, attacks targeting third-party providers continue to expose organizations to indirect data breaches.
The EY investigation serves as another reminder that protecting customer information requires strong security practices across the entire supply chain—not just within an organization's own infrastructure.
