EY filed breach notifications on July 15, 2026 disclosing a third-party ITSM platform breach that exposed personal and financial data from support ticket attachments between March 28 and April 12, 2026. The ticketing platform is now the exfiltration surface. A six-point playbook to run a secure outsourced help desk in 2026.
As reported by CyberInsider, GBHackers, SecurityAffairs and CyberNews, Ernst and Young filed breach notifications on July 15, 2026 with the California Attorney General and began mailing notice letters dated July 13, 2026. An unauthorized party accessed a third-party IT service management platform used by EY's tax practice between March 28 and April 12, 2026 and downloaded documents relating to a number of EY clients. EY detected anomalous activity on April 23, 2026, engaged an independent cybersecurity firm, and is offering complimentary Experian IdentityWorks identity monitoring. Exposed data included personal details tied to individuals' investment holdings with EY institutional clients and financial information contained in or used to prepare tax filings.
Because it concentrates sensitive data across many customers in one tenant, attachments outlive the ticket and are retained for years, access reviews on support tooling are typically weaker than on financial systems, and trusted integrations with identity providers, email, chat, CRM and monitoring pipelines widen the credentialed surface. A single foothold on the platform therefore yields cross-customer read access to a rich, years-deep archive of primary financial and personal data.
One, data minimisation inside tickets so sensitive documents never enter the platform in the first place. Two, attachment handling with DLP scanning and automated redaction. Three, short retention with automated purging of attachments after ticket closure. Four, least privilege plus tenant isolation plus MFA and SSO on the ITSM. Five, 24/7 anomaly detection and monitoring of the ticketing platform itself. Six, vendor due diligence on the ITSM or support-tool provider, including certifications, sub-processor register, right-to-audit clauses, incident-notification SLAs and encryption and key-custody terms.
Attachments should have a retention SLA independent of the ticket lifecycle. A defensible default is purging attachments a defined number of days after ticket closure, where the window is the shortest one compatible with the legal, tax and audit obligations of the ticket category. The ticket record itself is retained for the operational and audit clock; the attachments, which are what an attacker actually wants, are not. This is written into a retention schedule the audit committee can point at.
At a minimum: a written data-minimisation intake standard, an attachment handling policy with DLP and redaction, a documented attachment retention schedule with automated purging, SSO with phishing-resistant MFA and least-privilege scoping with tenant isolation on the ITSM, 24/7 monitoring of the ticketing platform itself with an escalation path to the buyer, and a vendor due-diligence pack on the underlying ITSM provider. A CNDP Law 09-08 and GDPR-aligned posture, a Data Processing Agreement referencing Article 28 obligations, and declared sub-processors with the same audit and notification obligations flowed down.
Call IT Dev operates outsourced technical support and cybersecurity engagements from Morocco with delivery depth in English, French, Spanish, Arabic and German across EU time zones, aligned with CNDP Law 09-08 and GDPR obligations. The engagement applies the six-point playbook end-to-end: a data-minimisation intake standard, a DLP and attachment-handling layer, a documented retention and auto-purge schedule, an SSO and MFA-enforced least-privilege access model with tenant isolation, 24/7 monitoring of the ticketing platform itself, and a vendor due-diligence pack on the ITSM provider layer, so the security posture and the customer experience live in the same contract.
CALL IT DEV — Software, AI and dedicated tech teams — Casablanca | Madrid | Dubai — contact@callitdev.com — +212-537-373777