Ernst & Young Got Breached Through Their IT Help Desk. Your Firm Could Too.

ShinyHunters compromised EY through a third-party ticketing platform. Support tickets contained client tax data. The same risk applies to any firm using outsourced IT tools.

Ernst & Young is one of the Big Four accounting firms. 400,000 employees. $50 billion in annual revenue. A security budget that dwarfs what most Iowa firms spend on their entire IT infrastructure.

They got breached through their IT help desk.

What happened

The ShinyHunters extortion gang compromised a third-party platform that EY used for IT service management. The attack window ran from March 28 through April 12, 2026. During that time, attackers accessed support tickets, which contained client tax information, and used stolen credentials from the platform to reach EY’s Jira, GitHub, and Azure environments.

The breach was disclosed publicly in late July. ShinyHunters has a track record of targeting professional services firms specifically because their internal systems contain concentrated client data.

Think about what lives in a support ticket at an accounting firm: “I can’t access the Johnson file,” with an attachment containing the tax return. “Client portal isn’t working for Smith Corp,” with account credentials pasted in the body. “Need to reset MFA for the new associate,” with enough identity information to impersonate them.

Support tickets are where people drop their guard. Nobody thinks of a help desk ticket as a security boundary. That’s exactly why attackers target them.

Why this matters for your firm

EY can survive this. They have breach response teams, cyber insurance with high limits, and a brand large enough to absorb the reputational hit. A 20-person CPA firm or 40-attorney law office doesn’t have that cushion.

The attack vector is the same tools many smaller firms use. Third-party IT platforms, shared credential stores, ticketing systems where sensitive information accumulates without anyone thinking about it. If your firm outsources IT (or uses any cloud-based support platform), you have a version of the same risk.

The ticketing system problem: Every time someone submits a help desk request, they’re potentially sharing sensitive information with whatever platform handles those requests. Client names, file paths, login credentials, screenshots of confidential documents. Over time, a ticketing system becomes an unintentional archive of exactly the information an attacker wants.

The credential chain problem: EY’s attackers didn’t stop at the ticketing system. They used credentials found there to access development tools (Jira), source code (GitHub), and cloud infrastructure (Azure). One compromised vendor led to lateral movement across multiple systems. This is the same pattern we covered when we wrote about what happens when your IT provider’s own tools get hacked. The tools meant to manage your environment doubled as the path into it.

The timing problem: The attack ran for two weeks before detection. Two weeks of an attacker reading support tickets, harvesting credentials, and moving through connected systems. For a smaller firm without dedicated security monitoring, that window could be months.

What your cyber insurance carrier cares about

If your firm’s cyber policy renews this fall, your underwriter is already asking questions about vendor risk management. The trend in insurance questionnaires has shifted from “do you have antivirus” to “how do you evaluate and monitor your third-party vendors.”

Common questions now appearing on applications and renewals:

  • Do you maintain a list of all third-party vendors with access to sensitive data?
  • Do you require vendors to carry their own cyber insurance?
  • Do you have a process for reviewing vendor security practices before onboarding?
  • Do you limit what data is shared with or accessible to each vendor?

If your firm can’t answer these questions, or if the honest answer is “no,” that’s a gap worth addressing before renewal, not after a claim.

Questions to ask this week

You don’t need to overhaul your vendor relationships overnight. But you should be able to answer these:

What’s in your ticketing system? Look at the last 50 support tickets your firm submitted (or that your staff submitted internally). How many contain client names, file references, login credentials, or screenshots with sensitive data visible? If the answer is “most of them,” that system needs to be treated as a sensitive data store, not a casual communication channel.

Who has access to your IT support platform? Not just your IT provider’s staff. What about the platform vendor’s employees? Subcontractors? Former employees whose access was never revoked? The EY breach happened through the vendor’s infrastructure, not through EY’s own network.

What credentials live in places they shouldn’t? Shared passwords in email threads, login details in support tickets, credentials in spreadsheets. These are the footholds attackers use to move from one compromised system into everything else. A password manager with role-based access isn’t glamorous, but it eliminates this entire category of risk.

When did you last review your vendor’s security posture? Not “do they have a SOC 2 report” (though that matters). More practically: do they patch their systems promptly? Do they use MFA internally? Do they encrypt data at rest? Do they notify you quickly if something goes wrong? EY’s vendor didn’t catch the breach for two weeks.

Better to sort this out before your insurance questionnaire forces the conversation, and well before a vendor breach makes the decision for you.


Artech Solutions manages IT security and vendor oversight for law firms and CPA firms across the Des Moines metro. If you’re not sure how your vendors handle your data, or whether your ticketing system is treated as the sensitive data store it is, we can help you sort that out.