EY Data Breach Exposes Goldman Sachs and Man Group Clients’ Data
An EY platform breach exposed tax and financial data linked to Goldman Sachs and Man Group clients.
Ernst & Young warned that an unauthorized party accessed a tax-services support platform between March 28 and April 12, 2026, and downloaded client documents. Exposed data included names, addresses, tax identification numbers, email addresses, and financial details tied to Goldman Sachs wealth-management clients and UK-listed hedge fund Man Group. Both firms said their own systems were not compromised. EY linked the incident to a Checkmarx vulnerability without naming a CVE, detected suspicious activity on April 23, notified regulators in California, Texas, Massachusetts, and Vermont, and is offering credit monitoring.
- Unauthorized access ran from March 28 to April 12, 2026; EY noticed it April 23.
- Stolen files held names, addresses, tax IDs, emails, and financial details.
- Goldman Sachs and Man Group said their own systems were not breached.
- EY blamed a Checkmarx flaw but named no CVE or exploit method.
- EY notified four US state regulators and is offering credit monitoring.
Full article593 words · extracted from cybersecuritynews.com · click to collapse
Ernst & Young (EY) has warned that a cyber breach exposed personal and financial information belonging to individuals linked to Goldman Sachs and Man Group. The incident affected a platform used to support EY’s tax services, rather than the financial firms’ own systems.
As the Financial Times first reported, the latest disclosures widen the known impact of the breach. Letters sent at the end of September said an unauthorized third party accessed the platform between March 28 and April 12, 2026, and downloaded documents connected to multiple EY clients.
The exposed information included names, addresses, tax identification numbers, email addresses, and financial details. Those affected include clients of Goldman Sachs’ wealth management business and the UK-listed hedge fund Man Group. The available reporting does not establish how many individuals associated with either firm were affected.
How the EY Breach Unfolded
EY first disclosed the incident in July and attributed it to a vulnerability in Checkmarx software. However, the reports reviewed do not identify a specific CVE, affected software version, or detailed exploit method. Those gaps limit what can currently be said about the technical entry point.
Cyber Security News’ earlier coverage described the affected system as a third-party IT service management platform. EY’s IT staff used it to support internal teams handling tax work, and support tickets included attachments containing sensitive client tax information. This placed client documents inside a support workflow outside the clients’ own networks.
EY detected unusual activity on April 23, eleven days after the last reported unauthorized access. Working with an independent cybersecurity firm, investigators determined that documents had already been downloaded during the March–April access window. The delay matters because the theft took place before EY identified the suspicious activity.
The incident illustrates how support systems can become a route to sensitive business data. In this case, access to a platform holding tax documents exposed information linked to several organizations without requiring a reported breach of those organizations’ internal systems.
Goldman Sachs said its systems were unaffected and that client assets remained safe. Man Group also confirmed that its systems were not compromised, describing the incident as involving third-party software used by EY. These statements distinguish the exposure of client information from a direct attack on either financial firm.
In a September 24 letter, Goldman Sachs told clients that EY had engaged an independent cybersecurity firm to verify the affected systems were secure. Goldman’s technology risk team was reviewing that work and had requested objective evidence and third-party checks showing that EY’s fixes were effective.
The available reports specifically attribute that demand to Goldman Sachs. They do not establish that Man Group made an identical request. EY said the incident did not affect its broader enterprise systems or threaten ongoing business operations, and that its review was nearing completion.
EY reported the breach to regulators in California, Texas, Massachusetts, and Vermont. It is offering affected individuals credit monitoring and identity protection services through a third-party provider.
EY’s July notice said it had no evidence that the exposed data had been misused or that particular individuals were deliberately targeted. That statement describes the findings at that stage, not a guarantee against later misuse.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.