GBHackers

EY Data Breach Exposes Goldman Sachs and Man Group Clients’ Tax and Financial Data


Ernst & Young (EY) has warned that a data breach exposed personal and financial information belonging to clients of Goldman Sachs’ wealth management division and Man Group. The incident involved a platform supporting EY’s tax services, not the financial firms’ own networks, according to client notifications reported by the Financial Times.

The latest disclosures expand the known impact of an incident first disclosed in July 2026. Global real estate developer Tishman Speyer also received notice that information linked to its investors might have been affected. EY said the incident did not reach its broader enterprise systems or threaten ongoing business operations.

How Client Data Was Exposed

Letters sent to affected individuals in late September said an unauthorized third party accessed the platform between March 28 and April 12, 2026. The intruder downloaded documents relating to several EY clients. Exposed information included names, addresses, tax identifiers, email addresses, and financial details, making the breach significant for people whose records were involved.

Our earlier coverage of the EY support platform breach explained that the system helped IT staff support internal teams handling tax work. Support tickets could contain attachments with sensitive client tax information. This placed financial records inside a support workflow, creating another location where client data needed protection.

EY detected unusual activity on April 23, eleven days after the last reported unauthorized access. An independent cybersecurity firm helped investigate and established that documents had already been downloaded. The firm filed a breach notification with California regulators on July 15 and also reported the incident in Texas, Massachusetts, and Vermont.

The Financial Times reported that EY attributed the incident to a vulnerability in Checkmarx software. However, the reporting reviewed does not establish a specific CVE, affected software version, or detailed attack method. Without those details, it would be premature to describe the exact exploit or connect it to a particular publicly known flaw.

ShinyHunters claimed responsibility in July through its dark web leak site. We previously reported the group’s EY breach claim, including allegations that credentials and files were stolen through a third party. Those statements remain attacker claims and should not be treated as independently confirmed findings about how access occurred.

Security Review And Client Impact

Goldman Sachs told clients on September 24 that EY had engaged an independent security firm to verify that affected systems were secure. The bank’s Technology Risk team was reviewing that work and requiring evidence and outside validation of EY’s fixes. Goldman said its systems were unaffected and client assets remained safe.

Man Group likewise said its systems were not compromised and that EY had notified affected individuals. EY said its review of exposed data was nearing completion and that findings were being shared directly with clients. Affected people were offered credit monitoring and identity protection through an outside provider.

The incident highlights a clear boundary: stolen tax documents do not mean investment accounts were accessed, but unaffected bank systems do not erase the exposure of client records. The available reports do not provide a complete victim count or establish that every affected individual lost the same information.

For financial firms, the case shows why vendor reviews must cover support tools and document attachments, not just core business systems. EY’s investigation and Goldman’s demand for verified fixes put attention on whether sensitive client data receives protection throughout the full service chain.

Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.



Source link