The Ernst & Young Cyberattack: Why Third-Party Risk Demands Penetration Testing

Another major organization has learned a difficult lesson: a company can have strong internal security controls and still become the victim of a breach through a trusted third-party platform. The recent Ernst & Young data breach highlights the risks associated with such third-party vulnerabilities.

Ernst & Young LLP, better known as EY, recently began notifying clients that sensitive personal and financial information was stolen from a third-party information technology service management platform. EY used the platform to support employees performing tax-related work, and support tickets sometimes included documents containing client tax information.

According to EYโ€™s breach notice, an unauthorized party accessed the platform between March 28 and April 12, 2026, and downloaded documents belonging to multiple clients. EY detected unusual activity on April 23, launched an investigation, secured the environment, brought in outside cybersecurity professionals, and notified federal law enforcement.

How Did the Attackers Get In?

EY has not publicly disclosed the initial attack method, the identity of the platform provider, or the attacker responsible. Therefore, it would be irresponsible to guess whether the breach began with stolen credentials, social engineering, an application vulnerability, a misconfiguration, or another technique.

What we do know is that attackers gained unauthorized access to a trusted platform and downloaded sensitive client documents.

That is the danger of third-party risk.

Attackers do not always have to break through your firewall. Sometimes they enter through a vendor, cloud platform, support system, software integration, or trusted account.

What Information Was Compromised?

The stolen documents contained personal and financial information used to prepare tax filings. Reported data included names, addresses, Social Security numbers, financial account numbers, credit or debit card numbers, and other tax-related information. EY has not publicly disclosed the total number of affected clients and has said it is not aware of misuse or additional exposure.

However, the absence of known misuse today does not mean the information has no value to criminals.

Tax records can give an attacker enough information to build a detailed profile of a victim. Criminals may use that data for identity theft, fraudulent tax filings, account takeover, targeted phishing, business email compromise, or convincing social engineering attacks.

Unlike a password, a Social Security number cannot simply be reset. Once this information leaves a protected environment, the risk can follow the victim for years.

A Third-Party Breach Is Still Your Breach

The EY incident reinforces a truth every organization must understand:

Outsourcing a service does not outsource the risk.

We saw a similar lesson during the Canvas cyberattack earlier this year. Canvas is operated by Instructure and used by schools and universities as a trusted learning platform. From the institutionโ€™s perspective, Canvas is a third-party vendor holding and processing its data.

Instructure reported that the attacker created a Free-for-Teacher account and submitted a support ticket containing malicious code. When a support representative opened the ticket, the code exploited a cross-site scripting vulnerability, allowed the attacker to obtain an authorization token, and provided elevated access. Information involved included usernames, email addresses, course names, enrollment information, and messages.

The schools did not create the Canvas vulnerability. However, their students, employees, operations, and reputations were still affected.

Your vendor may suffer the initial compromise, but your organization may still face disruption, notification obligations, loss of trust, legal exposure, and difficult questions from stakeholders.

Why Your Organization Still Needs a Penetration Test

Some leaders may believe a penetration test is unnecessary when a breach originated with a vendor.

That is the wrong conclusion.

A penetration test cannot guarantee that a third party will never be breached. However, it can determine whether a compromised vendor account, stolen token, exposed API, weak integration, or trusted connection could be used to attack your environment.

After a third-party incident, your organization should test its own defenses.

Can an attacker reuse vendor credentials? Are service accounts protected by multifactor authentication? Do integrations have more access than they need? Can a compromised account move laterally? Are sensitive systems properly segmented? Would your security tools detect unusual access or large data transfers?

Policies and automated scans cannot fully answer these questions. A professional penetration test safely simulates how a real attacker could take advantage of the trust relationships surrounding your organization.

Why Firma IT Solutions Is the Best Fit

Firma IT Solutions does not treat penetration testing as a compliance checkbox. We approach each engagement from the perspective of a real attacker while protecting the clientโ€™s operations and business continuity.

With more than 20 years of information technology and cybersecurity experience, certified ethical hacking expertise, and real-world incident response experience, Firma IT Solutions understands how technical weaknesses become business emergencies.

Our clients receive more than a list of vulnerabilities. We provide clear evidence, practical remediation guidance, technical reporting for IT teams, executive-level reporting for leadership, and a debrief that explains what the findings mean.

We can also evaluate risks created by remote access, cloud services, vendor connections, identity systems, APIs, and other third-party relationships.

The lesson from EY and Canvas is clear: you do not have to be directly attacked to become the victim of a cyberattack.

Your vendors are part of your attack surface. Your integrations are part of your attack surface. Every trusted connection must be tested.

The best time to find out how far an attacker could go is before a third-party breach gives them the opportunity.

Contact Firma IT Solutions at 303-209-0386 to schedule a professional penetration test and learn where your organization may be exposed.

, ,


Leave a Reply

Your email address will not be published. Required fields are marked *

About

Firma IT Solutions helps executives turn cybersecurity uncertainty into confidence. Through expert penetration testing, we uncover hidden vulnerabilities before criminals exploit them, protect critical operations, safeguard customer trust, and provide clear, actionable insight leaders can use to reduce risk, strengthen resilience, and make smarter security decisions before a breach occurs.

denver penetration testing

Tags

Social Icons