A support ticket exists to reproduce a problem, and reproducing a problem means attaching whatever the problem involved. Over years, a ticketing system quietly becomes one of the richest unstructured archives an organisation holds, and it is almost never classified as such.
Ernst & Young has been notifying clients of a breach caused by the compromise of a third-party support ticket platform used by its IT personnel. Reported access ran from late March into mid-April 2026. Documents attached to tickets were taken, with reporting describing tax filing data and personal and financial information among them.
Two Degrees From The Client
The chain here has an extra link. A client engaged a professional services firm; the firm used a support platform; the platform was compromised. Neither the client’s controls nor the firm’s own network were the failure point, and the client had no visibility into the third link at all.
For a professional services firm the exposure is specific: the material clients hand over is exactly the material that makes an attachment useful. Tax documents attached to a ticket about a filing error are not incidental to the ticket. They are the ticket.
The affected client count has not been disclosed and we are not estimating one. We grade this medium: the vector and window are consistently reported, the scope is not established.
Compiled from public reporting, listed below. Client counts have not been disclosed. Corrections: corrections@forensicpost.com.
- Data breach roundup (July 17–23, 2026)Privacy Guides
- List of recent data breaches in 2026Bright Defense