EY Client Data Exposure Highlights Overlooked Help Desk Security Risks, Chirag Goswami Reports

C

Chirag Goswami

LinkedIn Author

Founder @ Cybernara | Security-First Managed IT & Cloud Partner | Cloud, M365 & GRC | LinkedIn Top Voice

In a recent LinkedIn post, Chirag Goswami discusses a significant cybersecurity incident involving Ernst & Young (EY), highlighting critical vulnerabilities in the security of IT service-management platforms. Goswami’s analysis points to a broader issue of how these support systems can become unintentional repositories for sensitive client data.

The incident, which EY confirmed, involved unauthorized access to a third-party IT service-management platform used to support its tax operations. According to Goswami’s report, attackers gained access between March 28 and April 12, 2026, exposing support tickets that potentially contained personal, financial, and client tax documents.

“While the platform has since been secured, the incident exposed support tickets that may have contained personal, financial, and client tax documents.”

The Overlooked Vulnerability of Support Platforms

Chirag Goswami emphasizes that such support and help-desk platforms are frequently overlooked in comprehensive security reviews. This oversight is particularly concerning, as these platforms often store information far beyond their primary function of troubleshooting.

As Goswami points out:

“Support and help-desk platforms are often overlooked during security reviews, yet they frequently store documents and information far beyond their intended purpose.”

The implications of this, according to Goswami, are substantial. What begins as a simple support ticket can evolve into a critical data repository, putting sensitive customer information at risk if not properly managed. This situation underscores the need for organizations to treat these platforms with the same security rigor as primary customer databases.

Recommendations for Mitigating Risk

In his analysis, Chirag Goswami, writing under the banner of Cybernara Perspective, offers actionable insights for organizations to prevent similar incidents. He stresses the importance of recognizing that support tickets should be for problem-solving, not for accumulating sensitive data.

Goswami proposes several key measures:

  • Implementing strict attachment controls to limit the types of files that can be uploaded.
  • Employing automatic data redaction for sensitive information found within tickets.
  • Setting clear retention limits for support tickets to minimize the duration of data exposure.
  • Establishing secure file-sharing channels to ensure sensitive documents are handled appropriately.

According to Chirag Goswami, these steps are crucial for reducing unnecessary exposure and enhancing overall data protection strategies.

“Support tickets should solve problems not become a second customer database.”

EY has stated that the platform has been secured, relevant authorities have been notified, and there is currently no evidence that the exposed information has been misused. However, as Chirag Goswami highlights, the incident serves as a stark reminder of the potential security gaps in everyday business tools and the critical need for robust security practices across all organizational platforms.

The full scope of affected individuals has not been disclosed by EY, adding to the uncertainty surrounding the breach’s impact. Goswami’s reporting on this event provides valuable context for businesses to re-evaluate their own security postures, particularly concerning auxiliary systems that handle sensitive information.

📝 About This Content

This article is based on insights shared by Chirag Goswami on LinkedIn.

📅 Originally posted on July 27, 2026 | View original post on LinkedIn →