Established 2026Monday, 20 July 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageSecurity Desk
Security

Ernst & Young discloses data breach after support system hack

Ernst & Young disclosed a breach traced to a compromised third-party support-ticket platform — a reminder that outsourced ITSM tools remain a persistent blind spot in supply-chain security programmes.

Summary written by editorial AI · Source link below

Filed by BleepingComputer1 min readRead at source ↗

Ernst & Young is notifying customers of a data breach caused by the compromise of a third-party support ticket system used by its IT personnel. [...]

Editorial Analysis

Framed for the Compliance & GRC desk

Why it matters

A breach at EY via a third-party system raises questions about processor/sub-processor accountability under GDPR and NIS2 supply-chain obligations.

What to do

Verify that your third-party risk register reflects the EY incident and assess whether GDPR notification obligations apply to your organisation.

Board brief

EY's breach via a third-party support tool highlights supply-chain risk that NIS2 now requires boards to actively manage.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at BleepingComputer

External link — opens at BleepingComputer in a new tab.

§
Continue with

More from the Security Desk