
Third-Party Breaches Hit 48% in 2026: EY and a Swiss Fiduciary Leaked the Same Way
By, zero-adm
- 27 Jul, 2026
- 26 Views
In 2026 a third party was involved in 48% of all data breaches, and in 55% of breaches at small and mid-sized companies, according to Verizon’s Data Breach Investigations Report. In July, two textbook cases landed within days of each other. Ernst & Young, one of the largest advisory firms in the world, had client tax documents stolen because a third-party IT support platform was compromised. A fiduciary in Yverdon-les-Bains lost roughly 220 GB of client files to a ransomware crew. Neither attacker came through the front door.
A third-party breach is an incident where your data is exposed through a supplier’s system rather than your own. The supplier gets breached. The data, the notification duty and the phone calls from angry clients are still yours.
What happened at Ernst & Young?
EY disclosed in early July that a third-party IT service management platform used by its own IT staff had been compromised. In plain terms: the helpdesk system where employees open support tickets.
That detail is the whole story. Support tickets are not a database anyone thinks of as sensitive, but people attach things to them. In EY’s words, tickets “may include documents containing client tax information”. The notification filed with the California Attorney General lists names, addresses, Social Security numbers, account numbers, payment card numbers and other data used to prepare tax filings.
The timeline is worth reading twice. The intruder was inside between 28 March and 12 April 2026. EY spotted the unusual activity on 23 April. Clients were notified in early July. EY has not published how many people were affected, and is offering 24 months of identity monitoring and restoration through Experian.
On 27 July the extortion group ShinyHunters claimed the breach, saying it had obtained credentials through a supply-chain attack on an unnamed third party, and set a 31 July deadline. EY has not confirmed that attribution, and the claim has not been independently verified. Treat it as a claim, not a fact.
What happened to the fiduciary in Vaud?
In early July the ransomware group BravoX announced on its leak site that it had hit a fiduciary based in Yverdon-les-Bains. BravoX surfaced in January 2026 and runs the now standard double-extortion model: encrypt, exfiltrate, publish if nobody pays.
Nobody paid. On 18 July the group published around 220 GB of data, more than 100,000 files. Inside were dossiers belonging to private individuals, companies, institutions and roughly fifteen Vaud municipalities. Among the people whose tax data ended up on the dark web was Vaud State Councillor Vassilis Venizelos, together with his spouse. Within days the leak page showed close to 250 downloads.
The firm filed a criminal complaint and reported the incident to the cantonal data protection officer and to the Federal Office for Cybersecurity. That is the correct response, and it changes nothing for the fifteen municipalities whose files are already circulating.
Why do third-party breaches hit two very different firms the same way?
One is a global network with tens of thousands of security-cleared staff. The other is a regional fiduciary. They have almost nothing in common except the thing that actually mattered: both hold documents that belong to someone else, and both had those documents sitting somewhere outside the systems they were busy defending.
This is what the 48% figure looks like in practice. Your security programme covers your ERP, your mail, your endpoints. It rarely covers the ticketing tool, the outsourced payroll platform, the document portal the accountant uses, or the archive the IT partner keeps “for restores”. Those are the places where copies of confidential files accumulate quietly and nobody owns the risk. It is the same question that sits underneath digital sovereignty: not who promises to protect your data, but where it actually is.
For a professional services firm the maths is unforgiving. A single practice can hold the tax files of an entire town. When it leaks, the blast radius is not one company — it is every client on the list.
| Where you think the data is | Where it also is |
|---|---|
| Your ERP or practice management system | Attachments in support tickets |
| Your file server, encrypted and backed up | Your IT partner’s backup and restore archive |
| Your mailbox, under MFA | Shared portals and transfer links that never expire |
| Your systems, in your country | A SaaS tenant whose location nobody ever checked |
Our supplier is certified. Isn't that enough?
No, and this is the expensive misunderstanding. A certificate tells you a supplier had a defined scope audited on a given date. It does not tell you whether your files are in that scope, how long they are kept, who at the supplier can read them, or what happens to them when the contract ends.
EY is a firm that audits and advises on cyber risk for a living. That did not stop client documents leaving through a support platform. Certification is a reasonable filter for choosing a vendor. It is not a control, and it is not a defence when you have to explain the incident to your clients.
What to do on Monday: four moves
- List who holds your clients’ documents. Not the vendors you pay — the systems that actually contain files: ticketing, backup, payroll, e-signature, file transfer, the shared portal. One page, one owner per line. Most firms discover two or three entries they had forgotten.
- Ask each one three questions in writing. Where is our data stored, how long do you keep it, and how fast will you notify us if you are breached? A supplier who cannot answer in a week has answered.
- Stop sensitive documents from entering the wrong channel. Tickets, chats and email threads should reference a document, not carry it. Set the rule, then delete the historical attachments that are still sitting there. This one move would have shrunk both July incidents.
- Rehearse the notification, not just the restore. Decide today who calls clients, who talks to the authority and who speaks publicly if a supplier of yours is breached. In Switzerland the reporting clock starts when you learn of it, not when you finish investigating.
And in Switzerland?
Under the revised Federal Act on Data Protection (nFADP), the responsibility for personal data stays with the controller — you — even when the processing happens at a supplier. If a breach is likely to lead to a high risk for the people concerned, it has to be reported to the Federal Data Protection and Information Commissioner as soon as possible, and the affected people informed when needed. Outsourcing the processing does not outsource the duty.
The Vaud case shows the second-order effect that regulation cannot fix. Fifteen municipalities did nothing wrong. Their residents’ data is public anyway, because a supplier three steps down the chain had a bad month.
Frequently asked questions
What is a third-party data breach?
It is a breach where your data is exposed through a supplier’s system instead of your own. Verizon’s 2026 report found a third party involved in 48% of all breaches, and in 55% of breaches at small and mid-sized companies.
Are we liable if our supplier is the one who gets breached?
In most cases yes, as controller of the data. Under the Swiss nFADP and the GDPR the obligation to notify and to protect the people concerned follows the controller, not the vendor who lost the files.
How do we know which suppliers actually hold our documents?
Start from the file, not the contract. For each category of confidential document, trace every system it passes through or is copied into. Ticketing tools, backup archives and file-transfer links are the ones most often missed.
Does a certified supplier reduce the risk?
It reduces the chance of obvious gaps, but a certificate covers a defined scope at a point in time. It is not evidence that your specific data is protected, and it does not transfer your legal duty.
Is a small firm really a target?
Yes, and increasingly the preferred one. A small practice holding files for hundreds of clients gives an attacker a better return than one large company, which is exactly what happened in Vaud.
Sources
Verizon, 2026 Data Breach Investigations Report (third-party involvement in 48% of breaches, 55% for SMBs) · Ernst & Young breach notification filed with the California Attorney General, July 2026 · SecurityWeek, “Ernst & Young Data Breach Affects Personal, Financial Information”, July 2026 · BleepingComputer, “Ernst & Young data breach claimed by ShinyHunters extortion gang”, 27 July 2026 · Le Temps, “Le piratage d’une fiduciaire vaudoise expose sur le dark web 100 000 dossiers de clients”, July 2026 · 24 heures and 20 minutes, coverage of the Vaud fiduciary leak, July 2026 · inside-it.ch, “Cyberangriff legt Westschweizer Behördendaten offen”, 23 July 2026.
Recent Posts
- Third-Party Breaches Hit 48% in 2026: EY and a Swiss Fiduciary Leaked the Same Way
- AI Agent Security in 2026: 78% of Firms Already Hit — and Most Can’t Explain Why
- Chat Control: More MEPs Voted No Than Yes, and It Passed Anyway
- Time-to-Exploit Just Went Negative: Why Patching Is No Longer Enough in 2026
- EU AI Act: from 2 August 2026 you must disclose AI-generated content — what your business has to do
Category
- Cyber Security (92)
- Vulnerability Assessment (71)
Newest Posts
All Tag
2025 AI Automation Awareness Business CISO Compliance Cybercriminals CyberSecurity Academy Cybersecurity Awareness CyberSecurityRating Dataprotection EU AI Act Future GDPR Malware nFADP NIS2 nLPD Phishing Privacy Ramsonware Ransomware Supply Chain Threat Intelligence Treat Detection Vulnerability Assessment Vulnerability Management Zero-Day Zeroedge Academy
