When Your Auditor Gets Audited: The EY Breach and the Third-Party Blind Spot
Ernst & Young just became the cautionary tale it used to warn clients about.
Between March 28 and April 12, an unauthorized party accessed a third-party IT service management platform that EY's technology staff used to support tax-related work. The attacker downloaded client documents — tax filings containing Social Security numbers, financial account codes, and credit and debit card information. EY didn't spot the anomalous activity until April 23, eleven days after the attacker had already left. The firm started notifying affected clients in mid-July and is now facing a class action lawsuit in the Southern District of New York.
Let that timeline sit for a moment. Fifteen days of active exfiltration. Eleven more before anyone noticed. And three months before clients found out their most sensitive financial data had been stolen.
The Part That Should Worry You
This wasn't some obscure startup handling your data. EY employs 406,000 people, reported $53.2 billion in revenue last year, and operates in more than 150 countries. If you're a publicly traded company, there's a decent chance they touch your financials. And the breach didn't happen inside EY's core systems — it happened in a third-party platform that EY's own IT staff used to file support tickets. Some of those tickets had client tax documents attached.
That's the detail that matters most. The attack surface wasn't EY's audit methodology or its consulting practice. It was a help desk tool. A system so routine that nobody thought to ask whether client documents should be flowing through it, or whether the vendor operating it met the same security standards EY demands of itself.
In my experience, this is where most organizations get caught. Not by the risks they've assessed, but by the ones they never thought to assess. The IT service management platform was a tool for internal operations, not a client-facing system. It probably never showed up on a vendor risk assessment. And yet it became the conduit for one of the most damaging data exposures in Big Four history.
The Three Questions Your Board Should Be Asking
I've written before about the Three Questions framework — the questions every board member and executive should be able to answer about their cybersecurity posture. The EY breach puts all three into sharp focus.
Can we get hit? Every organization uses third-party platforms for internal operations. Ticketing systems, HR portals, collaboration tools, file-sharing services. Each one is a potential entry point, and most of them are invisible to the people making risk decisions. If your CISO can't tell you how many third-party platforms handle sensitive data — not just the ones in your vendor management program, but the ones your staff use day-to-day — then the answer to this question is yes.
Would we know? EY discovered the breach eleven days after the attacker stopped accessing the system. That's better than average, frankly. But “better than average” is cold comfort when your clients' Social Security numbers have been sitting on someone else's server for nearly a month. The question isn't whether you have monitoring. It's whether your monitoring covers the tools your people actually use, including the ones that weren't important enough to make it into the security architecture review.
Are we ready? EY's response followed the standard playbook — contain, investigate, notify, offer credit monitoring. But the class action lawsuit alleges that EY “knew, or should have known” that stronger protections were necessary. That phrase — “should have known” — is the one that keeps general counsels awake at night. It's not about whether you responded well after the breach. It's about whether you did enough to prevent it.
The Liability Clock Is Ticking
Here's the part that should get board attention. The lawsuit was filed Monday in the U.S. District Court for the Southern District of New York. The plaintiff's attorneys argue that EY, as “a sophisticated organization with the resources to deploy robust cybersecurity protocols,” failed to meet its obligations to protect client information. They're seeking class certification and monetary relief, and they estimate the affected population could number in the tens or hundreds of thousands.
This isn't theoretical anymore. SEC amendments to Regulation S-P, with a compliance deadline that just passed on June 3, 2026, elevate cybersecurity from an operational concern to a board-level accountability issue. Across the Atlantic, DORA and NIS2 are creating similar pressure. Regulators are moving, unmistakably, toward holding executives and board members personally accountable for third-party cyber risk.
If your organization shares sensitive client data with any third party — and every organization does — this is your problem. Not your CISO's. Not your CTO's. Yours.
What to Ask Your CISO This Week
If the EY breach does nothing else, let it prompt a conversation. Here are three questions to bring to your next security briefing:
- Which third-party platforms in our environment handle or could inadvertently receive sensitive client data? Don't accept the vendor management list. Ask about the tools your staff actually uses — the ticketing systems, the collaboration platforms, the shadow IT that nobody formally approved but everyone relies on.
- Do we have detection capabilities on those platforms, or are we relying on the vendor to tell us something went wrong? EY didn't discover the breach through its own monitoring of the third-party platform. If your answer is “we trust the vendor,” you're accepting a risk you may not fully understand.
- If a breach notification hit our desk tomorrow with our name on it as the affected party, what would our first 72 hours look like? Most organizations have incident response plans for breaches in their own systems. Far fewer have a plan for when their trusted partner is the one that got breached.
The EY breach is a reminder that cybersecurity risk doesn't stop at your firewall. It follows your data — into every vendor, every platform, and every support ticket that someone thought was too routine to worry about.