A Big Four firm got breached through its help desk software. Here's the lesson for sales teams
Extortion group ShinyHunters claims it breached EY through a third-party help desk platform, with a deadline set for July 31, 2026. The lesson applies to your stack.
By David Lara, Founder
Founder-reviewed ·How we research and correct articles
Ernst & Young detected anomalous activity inside a third-party IT service management platform on April 23, 2026 — a system its own staff used to manage support tickets for tax-related client work. The investigation traced unauthorized access back to a window between March 28 and April 12, 2026, during which documents tied to a number of EY’s clients were downloaded through the compromised support platform.
The story resurfaced hard in the last week of July, when the extortion group ShinyHunters publicly claimed responsibility on its dark-web leak site, posting a “final warning” and setting a deadline of July 31, 2026 to negotiate before releasing the stolen files. Reported categories of exposed data include names, addresses, Social Security numbers, bank account details, and other tax-preparation records tied to EY’s client base.
The part worth paying attention to isn’t the ransom deadline
Extortion deadlines make for a dramatic headline, but they’re the least useful part of this story for anyone running a business that isn’t EY. The useful part is the entry point: not EY’s core systems, not a phishing email that fooled a partner, but a support-ticket platform — the kind of software every mid-sized-and-up company runs, that almost nobody treats as sensitive infrastructure because it doesn’t feel like one.
That’s a structural blind spot, not a one-off mistake specific to EY. Support tools exist to make it easy for a customer or employee to hand over whatever context is needed to resolve a problem — which means, by design, they accumulate exactly the kind of sensitive attachments and account details that a security review of your “core” systems would flag immediately, if anyone thought to look at the helpdesk the same way.
A pattern, not an isolated incident
EY’s helpdesk compromise is one entry in a broader run of 2026 breaches that share the same shape: attackers reaching CRM or client data not by breaching the CRM directly, but by compromising a smaller, less-scrutinized connected tool that had legitimate access into it. It’s the same structural weakness behind the OAuth-token breach that hit a sales-intelligence platform’s customers this summer and the account-takeover chains documented in other major 2026 disclosures — different vendors, different data, same root cause: a connected tool with real access, treated as lower-risk than the systems it’s plugged into.
For a B2B sales or outbound team, the equivalent blind spots are easy to name once you go looking:
- A help desk or support tool where reps paste account details, screenshots of CRM records, or exported lead lists to explain an issue to IT.
- A scheduling or meeting-notes tool connected to your calendar and CRM, quietly holding transcripts of every discovery call.
- A Slack bot or workflow automation with write access to your CRM, authenticated with a token nobody’s rotated since it was set up.
- An enrichment or intent-data integration pulling contact records out of your CRM into a third-party platform for processing.
None of these feel like “the sensitive system.” Each one has real, standing access to sensitive data, and each one is a smaller, less-audited target than the CRM or email platform it’s connected to.
Why the “boring tool” pattern keeps working for attackers
There’s a straightforward economic reason this keeps happening rather than being a fluke that gets fixed after the first high-profile case. A CRM or email platform used by a major firm is a hardened target — heavily monitored, frequently audited, with a security budget sized to match how obviously valuable it is. The helpdesk platform plugged into it usually isn’t any of those things, because nobody budgets security review time for “the ticketing tool” the way they do for “the system with all our client data,” even when the ticketing tool has a standing, authenticated pathway into exactly that data. Attackers have noticed the mismatch between where the defensive attention goes and where the actual access lives, and they’re now systematically targeting the gap rather than the front door. EY is a large, well-resourced organization with a real security program — the fact that this still worked against a firm at that scale is the part smaller companies should take most seriously, not least seriously.
What to actually check this week
Scoping every integration credential to the narrowest permission it actually needs is the single change that would have limited the blast radius in nearly every breach of this shape this year, EY’s included — an ITSM platform that can only read ticket metadata, not download attached client documents, caps what a compromise of that specific tool can hand an attacker.
Where Norbelys fits
The reason Norbelys builds native integrations for HubSpot, Pipedrive, and Slack instead of leaving you to wire together generic connector tools is exactly this problem: a purpose-built integration can be scoped to precisely what a workflow needs — a new lead flowing in, a reply triggering a Slack alert — rather than granted broad, standing access “just in case” the way a generic automation platform often defaults to. Fewer connected tools with real access to your pipeline means fewer forgotten doors like the one that gave ShinyHunters a path into EY’s client data.
If this story has you auditing your own stack, see how Norbelys handles credentials and integration scope in practice — every plan includes the same integration set, so consolidating isn’t an upsell decision. Start sending with fewer connected tools holding standing access to your pipeline.
The EY breach and vendor risk — quick answers
What actually got breached at EY?
A third-party IT service management platform used internally to manage support tickets for tax-related client work, not EY's core systems directly. EY detected anomalous activity on April 23, 2026, and traced unauthorized access to a window between March 28 and April 12, 2026.
Who is ShinyHunters and what did they threaten?
ShinyHunters is an extortion group that publicly claimed responsibility for the breach on its dark-web leak site in late July 2026, setting a July 31, 2026 deadline to negotiate before threatening to release the stolen client documents.
Why does a helpdesk breach matter to a sales or outbound team that doesn't use EY's software?
Because the entry point — a support or connected tool nobody treats as sensitive, holding real access to client or CRM data — is a structural pattern, not an EY-specific mistake. Most sales stacks have an equivalent: a helpdesk, scheduling tool, or automation platform with standing CRM access that's rarely audited.
What's the practical first step to reduce this risk?
Open your CRM's connected-apps page and review every integration's scope and last-used date. Revoke anything unused, and scope every remaining integration to the narrowest permission it needs rather than the broadest one it was granted by default.