HomeCyber BalkansEY Data Breach Compromises Tax and Financial Information of Goldman Sachs and...

EY Data Breach Compromises Tax and Financial Information of Goldman Sachs and Man Group Clients

Published on

spot_img

Ernst & Young (EY) has issued a significant warning concerning a data breach that has compromised the personal and financial information of clients associated with Goldman Sachs’ wealth management division and the investment firm Man Group. According to reports from the Financial Times, this incident stemmed from a platform that supports EY’s tax services, rather than from the internal networks of the concerned financial firms.

This latest announcement sheds further light on a data breach originally disclosed in July 2026, revealing its broader implications. Global real estate developer Tishman Speyer was also notified that sensitive information linked to its investors may have been compromised. Notably, EY clarified that the breach did not affect its broader enterprise systems or jeopardize its ongoing business functions.

### How Client Data Was Exposed

In late September, letters were sent to affected individuals outlining how an unauthorized third party gained access to the platform from March 28 through April 12, 2026. During this time, the intruder managed to download various documents tied to multiple EY clients. The exposed data included crucial details such as names, addresses, tax identifiers, email addresses, and financial information, marking a serious breach for those whose records were implicated.

Previous reports on the EY support platform breach indicated that this system was primarily intended to assist IT personnel who supported internal teams handling tax-related work. Within this support framework, sensitive client tax information could reside in support tickets, creating an inadvertent storage location for critical financial records that necessitated stringent protection measures.

The anomaly raised by EY was detected on April 23, just eleven days following the last confirmed unauthorized access. An independent cybersecurity firm aided in the investigation and determined that documents had indeed been downloaded prior to the breach’s discovery. Subsequently, a breach notification was filed with California regulators on July 15, with similar notifications issued in Texas, Massachusetts, and Vermont as well.

The Financial Times reported that EY attributed the cause of the incident to a vulnerability found in Checkmarx software. However, the details regarding the specific software version affected or the exact method of attack were not fully disclosed. As a result, the current information does not allow for a definitive assessment of the exploit or its connection to any publicly recognized security flaw.

In July, the hacking group ShinyHunters claimed responsibility for the incident via their dark web leak site. Earlier reports confirmed the group’s assertion, including claims that they had stolen credentials and files via a third party. These assertions remain claims made by the attackers and have not been independently corroborated.

### Security Review and Client Impact

Goldman Sachs informed its clients on September 24 that EY had engaged an independent security firm to ensure that the affected systems were secure. Goldman’s Technology Risk team is actively reviewing the work conducted by EY, mandating evidence and external validation of the remediation measures taken. The bank confirmed that its own systems were not affected and that client assets remain secure.

Similarly, Man Group stated that its systems were not compromised and that EY had reached out to inform affected individuals. In the meantime, EY noted that its review of the exposed data was nearing completion, with findings being communicated directly to clients. Those impacted have been offered services for credit monitoring and identity protection through an external provider.

This incident underscores a crucial delineation: while the theft of tax documents does not imply that investment accounts were accessed, the fact that unaffected bank systems exist does not alleviate the risk posed by exposed client records. Current reports do not fully reveal the total number of victims or confirm that every affected individual lost the same information.

For financial institutions, this incident serves as a sharp reminder about the importance of conducting thorough reviews of third-party vendors, particularly those providing support tools and handling document attachments, beyond just core business systems. The ongoing investigation by EY, combined with Goldman’s insistence on verified fixes, highlights the pressing need for enhanced protection measures throughout the entire service chain involving sensitive client data.

In sum, the breach has spurred significant conversations about the importance of continuous security scrutiny, particularly when dealing with third-party vendors. The scrutiny applied to EY’s systems emphasizes the necessity for financial firms to bolster security practices and minimize vulnerabilities in their operations and those of their partners. As the understanding of the breach continues to evolve, stakeholders are left contemplating the long-term implications for client trust and industry standards in data protection.

Source link

Latest articles

Mistral Highlights Le Chonk as a Viable European Sovereign Model

French Hopes for Native European AI Highlight New Model's Cybersecurity Capabilities On October 6, 2026,...

OT Coalition Calls on CISA to Require Federal OT Security Measures

OT Cybersecurity Coalition Advocates for Mandatory Regulations The Operational Technology Cybersecurity Coalition (OTCC) has made...

South Korea Investigates Potential Use of AI Tool in Bank Customer Data Theft

Investigations Underway in South Korea After Data Breach at Multiple Banks Linked to AI...

Denmark’s National ID System Breach Exposes Personal Data of 8.8 Million

Denmark Strengthens Security Measures Following Major Data Breach In a significant security breach, Denmark is...

More like this

Mistral Highlights Le Chonk as a Viable European Sovereign Model

French Hopes for Native European AI Highlight New Model's Cybersecurity Capabilities On October 6, 2026,...

OT Coalition Calls on CISA to Require Federal OT Security Measures

OT Cybersecurity Coalition Advocates for Mandatory Regulations The Operational Technology Cybersecurity Coalition (OTCC) has made...

South Korea Investigates Potential Use of AI Tool in Bank Customer Data Theft

Investigations Underway in South Korea After Data Breach at Multiple Banks Linked to AI...