Ernst & Young (EY) Investigates Data Breach Involving Third-Party Support Tickets

2026-07-18T08:51:45Z132132f7f6487d0861b6db805a9760d8abeeca2ab61afbaf6a8d434b1342e93e
AI-assisted malwareCISA KEVChinese cyber espionageClaude CodeDeepSeekIoT botnetLegacyHiveRussian APTScattered SpiderStarland RATTuxBot v3UAT-11795WLDRWindows zero-daydata breachincident responselaw enforcementnetwork devicessupply-chainthird-party risktrojanized installers

What happened

Multiple high-impact security events and disclosures: Ernst & Young (EY) confirmed a data breach after a third‑party IT support ticketing system was compromised, exposing client documents and tax information. Japan’s food giant Nichirei suffered a disruptive cyberattack affecting logistics and shipments. Cisco Talos disclosed a Russian-speaking campaign (UAT-11795) distributing trojanized Zoom, Webex, and MobaXterm installers to deliver Starland RAT and the WLDR memory-only implant. CISA added known exploited vulnerabilities (including CVE-2023-4346) to its KEV catalog. Zoom patched a critical

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
132132f7f6487d0861b6db805a9760d8abeeca2ab61afbaf6a8d434b1342e93e
Enrichment time
2026-07-18T08:51:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Ernst & Young (EY) Investigates Data Breach Involving Third-Party Support Tickets · Baitaphish