All insights

30 July 2026

The breach came through the help desk

Why peripheral platforms — the ITSM tools nobody classifies — have become the softest route to your most sensitive client data.

The auditors got breached. Again. Not through their vaults - through their help desk.

Between 28th March and 12th April this year, someone spent fifteen days inside a support ticketing platform used by EY's tax teams. Not EY's core systems. The peripheral tool - the unglamorous place where IT staff attach client documents to explain a software problem and move on. Social Security numbers, financial account data, tax filings. Downloaded. Quietly. Nobody noticed for eleven days after the last access.

Regulatory notifications went out on 15th July. Eighty-four days after detection.

This is EY's third vendor-related breach in under three years. MOVEit in 2023 - Clop, a zero-day, Bank of America client data. A four-terabyte Azure backup exposed in 2025, sitting unencrypted on a public storage container. Now this. Every single incident traces back to the same structural gap: sensitive data accumulating inside a third-party platform that never received the scrutiny applied to EY's primary systems.

That is not bad luck. That is a pattern.

ITSM platforms earn their blind-spot status. They carry administrative access to internal systems ... by _design_ - and they accumulate sensitive attachments as an unintended consequence of doing their job.

An employee uploads a client document to explain a billing discrepancy. The ticket closes. The document stays. A year later, nobody knows it's there. The retention policy never included it. The last vendor risk assessment didn't cover it.

Security teams apply careful controls to databases and file servers. The platform serving those same teams tends to carry far lighter scrutiny - looser access controls, no data classification at the attachment level, retention settings nobody reviewed because nobody imagined it mattered.

The attackers imagined it.

Three things actually reduce this risk, in order of importance:

First :- classify at the point of attachment, not after the fact. Any platform that receives sensitive client documents must treat those attachments with the same controls as the system they came from. The moment a tax file enters a support ticket, it should carry access restrictions and a defined retention ceiling.

Second :- enforce deletion, not just policy. Six months of retention on sensitive attachments, automated and verified, removes the target. Policies that recommend deletion accomplish nothing without the enforcement mechanism to confirm it happened.

Third :- audit what your vendors can see, not just what your own applications do. The right question in a vendor assessment is not "how secure is their platform?" It is "what data of ours has accumulated inside it ... and who on their side can read it?" That question is rarely asked about ITSM tools. It should be the first one.

Every formal data store gets a control. Every platform surrounding it gets an assumption. That assumption is where the exposure lives.

ThirdPartyRiskGRCCyberSecurityDataProtectionCISO

Rituraj C. Buddhisagar

Principal Consultant, Defenaar Consulting · 30 July 2026

Follow on LinkedIn