← All articles

consultant

Ernst & Young: support ticket data leak — DLP for GDPR Art. 32 and cross‑border transfers

In July 2026, EY confirmed fraudulent access to a third‑party ticketing tool with tax documents downloaded. Here is a practical DLP to curb exfiltration and evidence GDPR compliance (Art. 32 and 44‑49).

Excerpt. In July 2026, EY confirmed fraudulent access to a third‑party ticketing tool with client tax documents downloaded. Here is a practical DLP that curbs exfiltration and evidences GDPR compliance (Arts. 32 and 44‑49).

The facts

On July 27, 2026, BleepingComputer reported that the extortion group “ShinyHunters” claimed an attack against Ernst & Young (EY), threatening to leak data if the company did not respond by July 31, 2026. Earlier in the month, EY disclosed an intrusion via an IT provider operating its ticketing platform: “unusual activity” was detected on April 23 and the attacker accessed the system between March 28 and April 12, downloading several documents. Tickets could contain personal and financial information used to prepare tax returns. The number of impacted individuals was not disclosed at publication time. Source: BleepingComputer, 27/07/2026.

Technically, the breach occurred in the supply chain: credentials were allegedly obtained at a third party and used to access the ITSM‑type support system, with exfiltration of ticket attachments (tax documents). EY did not name the specific vendor/service, but the sequence is clear: compromise of the provider account/platform, access to tickets, document downloads.

Why it matters in Luxembourg and across the EU: this scenario combines three common risks: 1) silent data exfiltration via third‑party SaaS (ticketing, CRM, support), 2) rich attachments (PDF/Excel) that are hard to control and harbor sensitive data, 3) potential extra‑EU transfer if the platform or its backups reside in the United States or elsewhere.

The applicable legal framework

  • GDPR Article 32 — security of processing: you must implement “appropriate technical and organizational measures” proportionate to risk, including preventing unauthorized disclosure of personal data. Official text: EUR‑Lex — Art. 32.
  • GDPR Articles 44‑49 — international transfers: any flow to a third country requires a legal basis (adequacy, SCCs/BCRs, derogation) and effective safeguards. This applies to extra‑territorial SaaS processors and their sub‑processors. Official text: EUR‑Lex — Chapter V, Arts. 44‑49. See also EDPB guidance on transfers: EDPS — International transfers.

For a concise overview of duties and required records, see our resources on GDPR obligations in Luxembourg.

In practice, EU regulators expect companies to demonstrate:

  • the effectiveness of access and exfiltration‑prevention controls across their SaaS estates and vendors (Art. 32),
  • flow mapping, contractual clauses, and “supplementary measures” for third‑country transfers (Arts. 44‑49),
  • rapid activation of notification procedures if the leak concerns EU data subjects (Arts. 33/34 GDPR) — in parallel, for NIS 2 entities in Luxembourg, notification to the ILR within 24/72h depending on impact, in line with NIS 2 obligations in Luxembourg.

The technical solution to deploy: modern DLP for SaaS and transfers

Goal: prevent or reduce exfiltration of personal data through support/ticketing platforms, email, and cloud storage, and provide evidence of appropriate measures (Art. 32) including in the context of cross‑border transfer risks (Arts. 44‑49).

How it works in practice:

  • Discovery and classification of data in tickets and attachments: GDPR patterns (identity, contact, TIN/VAT, financial, health), custom rules, OCR for scanned PDFs.
  • Inline controls on risky channels: attachments, comment fields, API downloads. Block, encrypt, or quarantine when a rule triggers (e.g., “tax data + unapproved external recipient”).
  • Contextualization by identity and location: stricter policies if the user is external (vendor), if the session originates outside the EU, or if the ticket subject contains sensitive keywords.
  • Logging and evidence: timestamp, rule applied, action taken, content hash. Essential to demonstrate “effectiveness” (Art. 32) and support transfer analysis.
  • Integration with IAM/MFA and CASB/CSPM: terminate risky sessions, restrict by device posture, block public link sharing, govern OAuth scopes used by third‑party apps.

Frameworks: ISO/IEC 27001 Annex A.8.12 (data leakage prevention), A.5.23 (supplier information security), A.8.10 (data security), NIST CSF 2.0 (PR.DS‑Exfil, PR.AC‑03), CIS Controls 3/4/13 (Data Protection, Access Control, DLP).

EY case in hindsight: with SaaS DLP enabled on the ticketing platform, mass exfiltration of attachments containing tax data could likely have been blocked, slowed, or at least fully traced (who, when, what, where), with SOC alerting and suspect sessions frozen. Source: BleepingComputer.

How Luxgap delivers this

  • Our ISO 27001 governance: align GDPR requirements (Arts. 32/44‑49), map processing and data flows, and define DLP policies per use case (tickets, support, email, storage).
  • Our 24/7 managed SOC: ingest DLP/SaaS alerts and logs, correlate by identity and geolocation, and run response playbooks (isolate the account, suspend OAuth tokens, block public sharing, trigger GDPR notification if needed). Explore our managed SOC for incident detection.
  • Our outsourced DPO and CISO consultants: verify transfer clauses (SCCs/BCRs), assess “supplementary measures,” and build the evidence pack (DLP logs, block decisions, transfer registers) usable before the CNPD; on governance, we can provide a certified DPO mandate.

Approach: 2–4 weeks of discovery and data mapping across key SaaS (support, CRM, Drive), then a DLP pilot on “tickets + email” with low‑friction policies (quarantine/justification), progressive hardening with SOC/IAM integration, then multi‑channel rollout.

Concrete case in Luxembourg or the EU

A local fiduciary (NIS 2 important entity, multi‑country exposure) deployed cloud DLP in 6 weeks across its support center and email. First‑quarter results: 1) automatic blocking of attachments with tax data sent to unapproved domains, 2) 70% reduction in public link sharing from the internal drive, 3) actionable logging that documented an unauthorized transfer to a non‑EU sub‑processor and fixed the contractual chain (SCCs + supplementary measures) with no notifiable incident.

Practical first steps

  1. Quickly map your support/ticketing platforms and their sub‑processors: where do data and backups reside? Outside the EU or not? Which transfer clauses (SCCs/BCRs) are in place.
  2. Enable minimal DLP rules on support and email: detect “tax identifiers + PDF/Excel” and quarantine for any unapproved external recipient.
  3. Close the OAuth door: audit connected apps (scopes and tokens), revoke unused access, and enforce phishing‑resistant MFA for privileged accounts.
  4. Wire into the SOC: forward DLP/SaaS logs and define an “attachment exfiltration” playbook (isolate, notify DPO, assess Arts. 33/34 GDPR, preserve evidence).
  5. Test the scenario: a 2‑hour exercise with IT, DPO, and Comms: simulated tax file leak via ticket; verify alerts, blocks, and notification readiness.

Official sources

Contact us to quickly assess your exposure and start a DLP pilot.

LUXGAP NEWSLETTER

Get our analyses the moment they drop.

GDPR, NIS 2, AI expertise articles, plus invitations to free webinars + trainings at Luxgap. 1 to 2 emails per week max, one-click unsubscribe.

Your data is never shared. GDPR-compliant (we're DPOs after all).

A question on this topic?

Our team usually replies within one business day. Configure your quote or write to us.

Build my quote →