EY Data Breach Exposes Personal and Financial Information Linked to Goldman Sachs and Man Group
EY data breach exposed personal and financial information linked to Goldman Sachs and Man Group clients through a third-party tax services platform.
Ernst & Young (EY) has warned that a cyber breach exposed personal and financial information linked to clients of Goldman Sachs and Man Group. The incident happened on a platform used by EY for its tax services and did not involve the internal systems of either financial company.
According to reports, an unauthorized third party accessed the EY platform between March 28 and April 12, 2026. During this period, the attacker downloaded documents connected to several EY clients. The exposed information included names, addresses, tax identification numbers, email addresses and financial details. The exact number of people affected has not been disclosed.
EY first reported the incident in July and said it was connected to a vulnerability in Checkmarx software. However, details about the exact software version and method used by the attackers have not been made public. The affected platform was used by EY employees to manage support work related to tax services. Some support tickets contained attachments with sensitive client tax information. This meant important documents were stored within a support system outside the affected companies' own networks. EY detected unusual activity on April 23, around 11 days after the reported unauthorized access ended. An investigation with an independent cybersecurity company later found that documents had been downloaded during the earlier access period.
Goldman Sachs said its own systems were not affected and that customer assets remained safe. Man Group also confirmed that its systems were not compromised. This means the incident was a third-party data breach, rather than a direct attack on Goldman Sachs or Man Group. However, sensitive information belonging to people connected to these companies was still exposed through EY's system.
Goldman Sachs asked EY to provide evidence that the affected systems had been properly secured after the incident. EY said its wider enterprise systems were not affected and that its investigation was nearing completion. The company has reported the incident to regulators in several US states and is offering affected individuals credit monitoring and identity protection services.
EY also stated it had not found evidence that the stolen information had been misused or that specific individuals were deliberately targeted. The incident highlights the growing third-party cybersecurity risks businesses face when sensitive customer information is handled through external platforms and service providers.
Information referenced in this article if from Cyber Security News