Ask most executives to picture a breach and they picture a wall being scaled — an attacker fighting through the firewall into the corporate network. It is a comforting image because it points inward, at systems the organisation controls and can fund. The 2026 record tells a less comfortable story. The wall held. The breach came through a side door the organisation had outsourced, forgotten, or never assigned an owner. Two of the year’s cleaner examples arrived within a fortnight of each other.
Ernst & Young: sensitive data in a support ticket
In mid-July 2026, EY — one of the Big Four — began notifying clients after an unauthorised party compromised a third-party IT service-management platform used by its internal IT staff to support teams doing client tax work. The firm filed breach notifications with the California Attorney General on 15 July.
Two details make it instructive. First, the exposed documents contained personal and financial information used to prepare tax filings — because support tickets on that platform routinely carried sensitive attachments. A risky-but-common enterprise habit became the whole breach. Second, the timeline: EY detected anomalous activity on 23 April, but investigation showed the intruder had been in the platform between 28 March and 12 April, downloading documents. Roughly three weeks of undetected access sat inside a system the firm did not itself operate.
Lidl: the supplier you never see
Days earlier, the Schwarz Group’s Lidl notified online-shop customers in Germany, Belgium and the Netherlands that a third-party service provider had suffered a security incident. Attackers briefly accessed a separately stored file of customer data — names, phone numbers, emails, dates of birth, customer numbers — and stole part of it. Lidl was explicit that its own online-shop system was not breached, and that passwords and payment data were not exposed. The honest framing, echoed across the coverage, is that a modern retailer’s exposure increasingly sits outside its own walls.
The same failure, across the globe, all year
EY and Lidl are not outliers. They are two points on a 2026 curve. The common thread is not a shared attacker — it is a shared blind spot: the third party, the dormant credential, the human, the connector nobody was watching.
Three of these deserve a closer look, because each names a distinct ownership failure:
- Klue (June 2026) — a market-intelligence SaaS vendor was breached through a forgotten legacy credential in its integration infrastructure. Attackers harvested OAuth tokens and reached the connected Salesforce environments of roughly two hundred downstream organisations, including well-known security vendors. Dormant access that was never decommissioned and never monitored is a recurring theme, not a one-off.
- Salesloft Drift (June 2026) — a parallel campaign abused OAuth tokens issued to a widely-used integration, reaching Salesforce data across hundreds of organisations. Critically, attackers found plaintext credentials — cloud keys, tokens, passwords — sitting inside support-case text. The same “secrets in the support system” failure that undid EY, at scale.
- Aura (March 2026) — an identity-protection company was breached after an attacker voice-phished an employee into granting access. The irony wrote its own headline, but the lesson is procedural: the strongest technical stack is one social-engineering call away when the human process has no clear owner or check.
The OSINT reading: most of this is visible before it is stolen
Here is the part that turns a news roundup into a control. A striking share of what these attackers exploited is discoverable from the outside, passively, before anyone breaks in. That is the entire premise of an external exposure assessment.
Dormant integrations and forgotten credentials leave footprints. Secrets committed to public repositories or embedded in exposed assets can be found without touching the target’s systems. Over-permissioned OAuth connections, exposed management interfaces, and third-party services quietly holding your data all sit in the attack surface a passive scan maps. The adversary is doing this reconnaissance already; the only question is whether the defender has looked first.
The GRC fix: ownership, not just tooling
The recurring word across these incidents is not “vulnerability.” It is ownership. A support platform accumulated sensitive attachments because no one owned what could ride along in a ticket. A legacy credential survived because no one owned its decommissioning. An OAuth connection kept standing authorisation because no one owned reviewing it. Tooling does not fix an accountability gap; governance does.
Closing The Outer Ring — Six Moves
- Maintain a live third-party and integration register. Every supplier, SaaS connector and OAuth grant that touches your data — with a named owner. Under CPS 230, material service providers already demand this discipline.
- Assign an owner to every credential and token. Ownership carries the duty to review and decommission. Dormant, unowned access is the Klue failure in miniature.
- Govern what enters support systems. Treat support tickets and case notes as data stores. Block sensitive attachments and plaintext secrets — the EY and Salesloft lesson.
- Run periodic passive external exposure assessments. See your third-party footprint, exposed interfaces and leaked secrets the way an attacker does — before the attacker acts.
- Review OAuth and integration permissions on a cadence. Standing authorisation is standing risk. Revoke what is unused; least-privilege what remains.
- Pre-map notification obligations to third parties. Under the Privacy Act / NDB scheme, a supplier’s breach can still be your notifiable event. Know the trigger before the clock starts.
The organisations that came through 2026 well were not the ones with the highest walls. They were the ones that had looked outward — that knew which suppliers held their data, which credentials were still live, and which connectors could reach their crown jewels. Internal focus is not wrong; it is incomplete. The breach is increasingly not a wall being scaled. It is a door you outsourced, and forgot you owned.
Sources & references
- Ernst & Young discloses data breach after support-system hack — BleepingComputer
- EY third-party IT support platform compromise: analysis — Rescana
- Lidl discloses online-shop breach after service-provider hack — BleepingComputer
- Lidl customer data stolen from external service provider — The Record
- Klue breach exposes Salesforce data across the SaaS supply chain — Nudge Security
- Salesloft Drift OAuth token breach (UNC6395) — Rescana
- About the Notifiable Data Breaches scheme — OAIC
- APRA — Prudential Standard CPS 230 Operational Risk Management