Client tax files sat as attachments in an IT help desk tool. Nobody was watching them there.
Client tax files sat as attachments in an IT help desk tool. Nobody was watching them there.
Ernst & Young is notifying clients that documents containing their tax data were downloaded from a third-party support ticket system used by the firm's IT staff, BleepingComputer reported on July 17. An unauthorized party had access to the platform between March 28 and April 12. EY detected the anomalous activity on April 23 and brought in outside investigators. This week the story sharpened. On July 27 the ShinyHunters extortion group added EY to its leak site, claimed the intrusion and gave the firm until July 31 before it publishes the stolen files, according to BleepingComputer.
The headline will read as one more third-party breach. The detail worth your attention sits one layer down. Client tax documents were living in a help desk tool.
How did client tax data end up in a help desk system?
The mechanics are ordinary, which is exactly why they're worth studying. EY's IT personnel used a third-party service management platform to support internal teams handling client tax work. When staff filed tickets, they attached whatever files were needed to resolve the issue. Per the notification letter EY filed with the California Attorney General, some of those attachments contained personal and financial data used to prepare tax filings.
None of this required a policy failure. Data follows work. A document that starts life in a governed tax platform gets attached to a ticket. The ticketing system quietly becomes a store of regulated client data. Nobody classified it there. Nobody watched it move. The controls stayed behind with the original copy.
EY has since secured its systems, notified federal law enforcement and offered affected clients 24 months of identity monitoring through Experian, per BleepingComputer. What the firm hasn't been able to say publicly is how many clients were affected. That's what happens when data turns up somewhere no inventory was looking.
Why is third-party risk a data visibility problem?
The pattern extends well past one firm. Verizon's 2026 Data Breach Investigations Report found that third parties were involved in 48% of breaches, a 60% rise year over year. Verizon points to unglamorous root causes such as misconfigured MFA and excessive access permissions far more often than sophisticated tradecraft.
Vendor questionnaires won't catch this class of exposure. They assess the vendor's controls. They say nothing about which of your sensitive files have drifted into that vendor's platform through everyday work. That inventory is the difference between reading about a ticketing breach in the news and knowing the same day exactly which clients need a phone call.
How do you protect data you didn't know was there?
Start from the data rather than the perimeter. MIND continuously discovers and classifies sensitive data across SaaS applications, endpoints and email, then keeps watching as files move between them. Context does the heavy lifting here. A tax return attached to an IT ticket carries a different risk than the same file inside the platform built to hold it. A context-aware classification engine can tell the two apart before an analyst ever gets paged.
We aren't merely indexing files. We're minding where client data actually lives, so a copy sitting in a support queue shows up in your inventory months before it could show up in a notification letter.
The EY breach won't be the last time sensitive data surfaces in a system nobody thought of as a data store. If your inventory ends at the platforms designed to hold sensitive data, this is a good week to look wider. See what MIND finds in your environment.










