Ernst & Young (EY) has revealed that a cyberattack compromised the personal and financial details of individuals connected to Goldman Sachs and Man Group. The breach targeted a platform EY uses for its tax services—not the internal networks of the financial firms themselves.
What Happened
In late September, EY disclosed that an unauthorized party gained access to its tax services support platform between March 28 and April 12, 2026, downloading documents tied to multiple clients. The data exposed included names, addresses, tax ID numbers, email addresses, and financial details. While some of the affected individuals were clients of Goldman Sachs’ wealth management division and Man Group, the exact number has not been determined.
Where the Attack Unfolded and How
The breach stemmed from a vulnerability tied to third-party software provided by Checkmarx, though EY has not released a specific vulnerability identifier (CVE), version affected, or precise exploitation method. The platform compromised is used in EY’s internal workflow—it’s an IT service management tool handling support tickets, which sometimes contained attachments with sensitive tax data. Those attachments sat outside the security boundaries of the clients’ own systems.
Detection, Response, and Impact
EY first noticed unusual activity on April 23—eleven days after the attackers’ last known access. An independent cybersecurity firm later confirmed that documents were downloaded during the breach window. Both Goldman Sachs and Man Group have insisted that their systems weren’t breached; the issue was with EY’s third-party platform.
Goldman Sachs informed clients on September 24 that EY had retained independent experts to audit and secure the compromised systems. Goldman’s team also asked for proof—objective assessments and third-party verification—of those fixes. It’s not clear whether Man Group demanded the same level of validation.
Regulatory Steps & Assurance Measures
EY has reported the incident to authorities in California, Texas, Massachusetts, and Vermont. The firm is also offering affected individuals credit monitoring and identity protection services through a third party. In its initial public communication, EY said it found no evidence that data was misused or that any specific individual was targeted—though this assessment applies only to the investigation so far, not guarantees about future misuse.
Wider Implications
This breach highlights the risk posed by third-party platforms—even when an organization’s own systems remain intact. EY’s case shows how support workflows, ticketing systems, or tax service tools can become gateways to sensitive data if not properly isolated or monitored.
For Goldman Sachs and Man Group, the incident underscores a growing need to demand visibility and verification in vendor and partner security protocols—especially with tools that touch financial, tax, or identity data.
Looking ahead, clients and regulators will be watching how EY closes the vulnerabilities, whether post-breach assessments verify that all gaps have been secured, and whether monitoring catches any evidence of data misuse. The real measure here is how firms react—not just how they report.