EY breach exposed tax data of Goldman Sachs and Man Group clients
TLDR
- Accounting firm EY has told clients that a breach of a third-party IT platform exposed personal and financial data tied to Goldman Sachs' wealth management business and hedge fund Man Group.
- An unauthorised party accessed the platform between 28 March and 12 April 2026 and downloaded documents; EY only detected the activity on 23 April, 11 days after the last unauthorised access.
- Exposed data includes names, addresses, tax identification numbers, email addresses and financial details; EY has not said how many individuals at either firm were affected.
- Goldman Sachs and Man Group both say their own systems were not compromised and client assets remain safe; Goldman says it has asked EY for independent evidence that the issue has been fixed.
EY first disclosed the incident in July, attributing it to a vulnerability in Checkmarx software, though available reporting does not identify a specific CVE or exploit method.1 The affected system was a third-party IT service management platform that EY's internal teams used to support tax work, with support tickets carrying attachments that included sensitive client tax documents, placing that data inside a support workflow outside the clients' own networks.1 As the Financial Times first reported, letters EY sent at the end of September widened the known scope of the breach to clients of Goldman Sachs' wealth management division and UK-listed hedge fund Man Group.1
EY detected unusual activity on 23 April, 11 days after the last reported unauthorised access on 12 April, and working with an independent cybersecurity firm determined that documents had already been downloaded during the March to April access window.1 The exposed information includes names, addresses, tax identification numbers, email addresses and financial details.1
A Goldman Sachs spokesperson said the attack "left the bank's own systems untouched" and that client assets had not been put at risk and "remain safe," adding: "As with other clients we understand were affected, we have been in regular contact with EY and are focused on working with them to support any of our clients impacted by their security incident."2 Man Group similarly said its own systems were not compromised, describing the incident as involving third-party software used by EY.1 In a 24 September letter, Goldman Sachs told clients that EY had engaged an independent cybersecurity firm to verify the affected systems were secure, and that Goldman's technology risk team was reviewing that work and had requested objective, third-party evidence that EY's fixes were effective.1 Bloomberg, which first reported Goldman's involvement, said EY had not returned its request for comment.2
EY reported the breach to regulators in California, Texas, Massachusetts and Vermont, and is offering affected individuals credit monitoring and identity-protection services through a third-party provider.1 The company's July notice said it had no evidence the exposed data had been misused or that specific individuals were deliberately targeted, a statement describing findings at that stage rather than a guarantee against later misuse.1
Why it matters: the breach never touched Goldman Sachs' or Man Group's own networks, yet their clients' tax and financial data still ended up exposed through an EY support platform, showing how a single compromised vendor tool can leak sensitive data belonging to multiple blue-chip financial firms at once.
Sources
- EY Data Breach Exposes Goldman Sachs and Man Group Clients' Data (Cyber Security News)
- Goldman Sachs client data exposed in EY data breach (Quartz)