Ernst & Young (EY) has disclosed a cybersecurity incident that compromised personal and financial data associated with clients of Goldman Sachs and Man Group. The breach targeted a platform integral to EY’s tax services, rather than the financial institutions’ own systems.
Details of the Data Breach
The Financial Times initially reported on the breach, highlighting its broader impact. According to letters distributed in late September, an unauthorized entity accessed the platform from March 28 to April 12, 2026, extracting sensitive documents tied to various EY clients.
The compromised data included names, addresses, tax IDs, email addresses, and financial information. Clients from Goldman Sachs’ wealth management division and the UK-listed hedge fund Man Group were among those affected. The exact number of impacted individuals remains unspecified.
Technical Aspects of the Breach
EY first announced the incident in July, attributing it to a vulnerability in Checkmarx software. However, specifics regarding the exploited software version or method remain undisclosed, limiting the understanding of the breach’s technical mechanism.
Previous reports by Cyber Security News identified the affected system as a third-party IT management platform used by EY’s staff to manage tax-related support. This system, containing sensitive client information, was outside the direct control of clients’ networks.
EY detected unusual activity on April 23, signaling a delay in identifying the security threat. An independent cybersecurity firm confirmed that document extraction had occurred within the March-April window, emphasizing the importance of timely detection.
Responses and Measures Taken
Goldman Sachs assured that their systems were unaffected, with client assets remaining secure. Man Group echoed similar sentiments, clarifying that the breach involved third-party software utilized by EY, not their internal systems.
Goldman Sachs informed clients via a September 24 letter that EY had partnered with an external cybersecurity firm to ensure the security of affected systems. They are reviewing these efforts, requesting evidence and third-party validation of EY’s corrective measures.
EY has communicated the breach to regulatory bodies in California, Texas, Massachusetts, and Vermont, offering credit monitoring and identity protection to those affected. The firm reported no signs of data misuse or targeted attacks on specific individuals, though this does not preclude future risks.
The incident underscores the vulnerability of support systems in exposing sensitive data, highlighting the need for robust cybersecurity measures to protect client information.
