CyberSecurityNews

EY Data Breach Exposes Goldman Sachs and Man Group Clients’ Data


Ernst & Young (EY) has warned that a cyber breach exposed personal and financial information belonging to individuals linked to Goldman Sachs and Man Group. The incident affected a platform used to support EY’s tax services, rather than the financial firms’ own systems.

As the Financial Times first reported, the latest disclosures widen the known impact of the breach. Letters sent at the end of September said an unauthorized third party accessed the platform between March 28 and April 12, 2026, and downloaded documents connected to multiple EY clients.

The exposed information included names, addresses, tax identification numbers, email addresses, and financial details. Those affected include clients of Goldman Sachs’ wealth management business and the UK-listed hedge fund Man Group. The available reporting does not establish how many individuals associated with either firm were affected.

How the EY Breach Unfolded

EY first disclosed the incident in July and attributed it to a vulnerability in Checkmarx software. However, the reports reviewed do not identify a specific CVE, affected software version, or detailed exploit method. Those gaps limit what can currently be said about the technical entry point.

Cyber Security News’ earlier coverage described the affected system as a third-party IT service management platform. EY’s IT staff used it to support internal teams handling tax work, and support tickets included attachments containing sensitive client tax information. This placed client documents inside a support workflow outside the clients’ own networks.

EY detected unusual activity on April 23, eleven days after the last reported unauthorized access. Working with an independent cybersecurity firm, investigators determined that documents had already been downloaded during the March–April access window. The delay matters because the theft took place before EY identified the suspicious activity.

The incident illustrates how support systems can become a route to sensitive business data. In this case, access to a platform holding tax documents exposed information linked to several organizations without requiring a reported breach of those organizations’ internal systems.

Goldman Sachs said its systems were unaffected and that client assets remained safe. Man Group also confirmed that its systems were not compromised, describing the incident as involving third-party software used by EY. These statements distinguish the exposure of client information from a direct attack on either financial firm.

In a September 24 letter, Goldman Sachs told clients that EY had engaged an independent cybersecurity firm to verify the affected systems were secure. Goldman’s technology risk team was reviewing that work and had requested objective evidence and third-party checks showing that EY’s fixes were effective.

The available reports specifically attribute that demand to Goldman Sachs. They do not establish that Man Group made an identical request. EY said the incident did not affect its broader enterprise systems or threaten ongoing business operations, and that its review was nearing completion.

EY reported the breach to regulators in California, Texas, Massachusetts, and Vermont. It is offering affected individuals credit monitoring and identity protection services through a third-party provider.

EY’s July notice said it had no evidence that the exposed data had been misused or that particular individuals were deliberately targeted. That statement describes the findings at that stage, not a guarantee against later misuse.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC



Source link