When Your Trusted Advisor Gets Breached
Ernst & Young — one of the Big Four firms that companies hire specifically to help manage risk — just disclosed that an unauthorized party accessed a third-party IT platform used to support their tax-related work and downloaded client documents containing Social Security numbers, financial account information, and tax records.
Let that sink in for a moment. The firm you trust to handle your most sensitive financial data got compromised through a vendor's help-desk platform.
What Happened
Between March 28 and April 12, 2026, an attacker accessed a third-party IT service management platform that EY's technology personnel use to support tax-related client work. EY detected anomalous activity on April 23 — eleven days after the unauthorized access ended. Notification letters didn't go out to affected individuals until July 13, nearly three months after detection.
The exposed data included names, addresses, dates of birth, Social Security numbers, driver's license numbers, and financial account information tied to tax filings. EY has filed breach notifications in multiple states — 873 affected individuals in Texas, 480 in Massachusetts, 13 in Vermont — though the full scope remains undisclosed. A proposed class action has already been filed in the U.S. District Court for the Southern District of New York.
No ransomware group has claimed responsibility, and the specific method of compromise hasn't been disclosed. But the pattern is familiar: an attacker found a softer target in the supply chain and used it to reach the real prize.
Why This Should Concern Every Executive
In Cyber Risk Is Business Risk, I write about the Three Questions that every executive should be able to answer about their organization's cyber posture. The EY breach puts a sharp point on one of them: Do you know where your data actually lives?
Most executives can answer that question for their internal systems. Fewer can answer it for every vendor, subcontractor, and service provider that touches their data. EY's clients didn't hand their Social Security numbers to some unknown startup. They handed them to one of the most respected professional services firms on the planet. And that firm, in turn, relied on a third-party help-desk platform that became the entry point.
This is the supply chain risk problem at its most uncomfortable. You can't outsource accountability.
The Regulatory Walls Are Closing In
The SEC's amended Regulation S-P — which requires covered institutions to establish incident response programs, notify customers of breaches within 30 days, and formally oversee service providers — hit its final compliance deadline on June 3, 2026 for smaller entities. Larger entities have been subject to these rules since December 2025.
The SEC has made cybersecurity a board-level accountability issue. Directors and officers who didn't ask appropriate questions or demand adequate reporting face scrutiny under the same Caremark standard that governs other fiduciary duties. You can't delegate away liability by outsourcing the IT function — you remain responsible for ensuring vendors meet security standards and for monitoring their performance.
That's not a theoretical risk anymore. It's an active enforcement posture.
The Patch Tsunami Makes It Worse
Here's the other piece of the July 2026 picture that boards need to understand. Microsoft's July Patch Tuesday addressed 570 vulnerabilities — the largest single update in the company's history — including three zero-day flaws, two of which were already being actively exploited before patches were available. Oracle shipped 1,449 security patches in its July Critical Patch Update, also a record, covering more than 1,200 vulnerabilities across 32 product families. Roughly 600 of those Oracle flaws could be exploited remotely without valid credentials.
Your organization runs Microsoft products. Your organization almost certainly runs Oracle somewhere. So do your vendors, your auditors, and your law firm.
When the attack surface is expanding this fast, third-party risk isn't a compliance checkbox. It's the primary way your data gets stolen.
What to Ask Your CISO This Week
If the EY breach and July's record-breaking patch cycle don't prompt a conversation with your security leadership, I'm not sure what will. Here's where to start:
"Which third parties have access to our most sensitive data, and when was the last time we verified their security controls?" Not their SOC 2 report from 18 months ago. Their actual, current security posture — including the sub-vendors they rely on.
"How quickly would we know if one of those third parties was compromised?" EY's attacker had access for 15 days. Detection came 11 days after the access ended. Your board should know whether your organization could detect a similar compromise faster — and be honest about the answer.
"Are we in compliance with the SEC's amended Regulation S-P?" If your organization falls under SEC jurisdiction, the compliance deadline has passed. If you're not compliant, that's a conversation that needs to happen now, not after the next breach makes headlines.
"What does our patch cadence look like for critical and zero-day vulnerabilities?" With 570 Microsoft patches and 1,449 Oracle patches landing in a single month, your security team is triaging under pressure. Understand their process and whether they have the resources to keep up.
The Bigger Picture
In my experience, the organizations that handle third-party risk well share one trait: their boards treat vendor oversight as a standing agenda item, not something that gets attention after a breach. They ask specific questions. They expect documented answers. They follow up.
The EY breach is a reminder that no brand name, no matter how prestigious, guarantees security. Your data is only as safe as the weakest link in the chain that touches it — and most organizations don't even know how long that chain is.
Start mapping it. Start asking the hard questions. And don't wait for your name to show up in a breach notification to do it.