Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
EY Data Breach Exposes Goldman Sachs, Man Group Client Data
October 7, 2026
Anthropic’s Claude AI now available to cybersecurity red teams
October 7, 2026
Critical Apache Struts Flaws Allow Remote Code Execution
October 6, 2026
Home/CyberSecurity News/EY Data Breach Exposes Goldman Sachs, Man Group Client Data
CyberSecurity News

EY Data Breach Exposes Goldman Sachs, Man Group Client Data

Key Takeaways Ernst & Young (EY) confirmed a data breach impacting a third-party platform used for its tax services. Personal and financial data belonging to clients of Goldman Sachs and Man...

David kimber
David kimber
October 7, 2026 4 Min Read
2 0

Key Takeaways

  • Ernst & Young (EY) confirmed a data breach impacting a third-party platform used for its tax services.
  • Personal and financial data belonging to clients of Goldman Sachs and Man Group were exposed.
  • The breach occurred between March 28 and April 12, 2026, with detection on April 23, 2026.
  • The incident stemmed from a vulnerability in Checkmarx software, though specific details remain undisclosed.
  • Affected individuals are being offered credit monitoring and identity protection services.

EY Data Breach Exposes Financial Client Data

Professional services giant Ernst & Young (EY) has confirmed a significant cyber breach that exposed sensitive personal and financial information belonging to individuals associated with Goldman Sachs and Man Group. The incident did not compromise the internal systems of these financial firms but rather affected a platform utilized by EY to support its tax-related services.

Table Of Content

  • Key Takeaways
  • EY Data Breach Exposes Financial Client Data
  • Understanding the Breach’s Genesis
  • What You Should Do

As the Financial Times first reported, recent disclosures have broadened the scope of the breach’s impact. Communications sent to affected parties in late September revealed that an unauthorized entity accessed the platform between March 28 and April 12, 2026, and proceeded to download documents linked to numerous EY clients.

The compromised data included names, residential addresses, tax identification numbers, email addresses, and detailed financial information. Among those impacted were clients of Goldman Sachs’ wealth management division and the UK-listed hedge fund Man Group. Current reporting does not specify the exact number of individuals from either firm whose data was exposed.

Understanding the Breach’s Genesis

EY initially acknowledged the security incident in July, attributing it to a vulnerability within Checkmarx software. However, comprehensive details regarding a specific CVE identifier, the affected software version, or the precise exploit methodology have not been publicly disclosed. This lack of specificity limits a full technical understanding of the entry point.

Earlier reports indicated the compromised system was an external IT service management platform. EY’s internal IT teams leveraged this platform to facilitate their tax work, and support tickets often contained attachments with sensitive client tax documentation. This operational setup inadvertently placed confidential client documents within a support workflow, external to the clients’ own secure networks.

EY’s security teams identified unusual activity on April 23, 2026, which was eleven days after the final reported instance of unauthorized access. Collaborating with an independent cybersecurity firm, investigators subsequently determined that data had already been exfiltrated during the March-April access window. The delay between the data theft and its detection is a critical factor in understanding the incident’s timeline.

This incident underscores the inherent risks associated with third-party support systems, which can become conduits for accessing sensitive business data. In this particular case, unauthorized access to a platform housing tax documents resulted in the exposure of information linked to multiple organizations, without necessitating a direct breach of those organizations’ internal IT infrastructures.

Both Goldman Sachs and Man Group have affirmed that their proprietary systems remained secure and were not compromised. Goldman Sachs confirmed the safety of client assets, while Man Group described the incident as involving third-party software used by EY. These statements distinguish the exposure of client information from a direct cyberattack on either financial institution.

In a letter dated September 24, Goldman Sachs informed its clients that EY had engaged an independent cybersecurity firm to validate the security of the affected systems. Goldman’s technology risk team is actively reviewing this assessment and has requested objective evidence and third-party verification to confirm the effectiveness of EY’s implemented remediations. While Goldman Sachs specifically made this demand, reports do not indicate whether Man Group issued a similar request. EY has stated that the incident did not impact its broader enterprise systems or ongoing business operations, and its internal review is nearing completion.

EY has reported the breach to regulatory bodies in California, Texas, Massachusetts, and Vermont. The firm is providing affected individuals with complimentary credit monitoring and identity protection services through a specialized third-party provider. EY’s July notice stated that at that time, there was no evidence of the exposed data being misused or that specific individuals were deliberately targeted. This statement reflects the findings at that stage of the investigation and does not preclude potential future misuse.

What You Should Do

  • Monitor Financial Statements: Regularly review bank statements, credit card activity, and credit reports for any suspicious or unauthorized transactions.
  • Utilize Credit Monitoring: Take advantage of the credit monitoring and identity protection services offered by EY, if you are an affected individual.
  • Be Wary of Phishing: Exercise extreme caution with unsolicited emails, calls, or messages, especially those requesting personal or financial information, as threat actors may leverage exposed data for targeted phishing attacks.
  • Update Passwords: Consider updating passwords for critical financial accounts, particularly if any exposed information could be used for password reset attempts.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachCVECybersecurityExploitSecurityThreatVulnerability

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Anthropic’s Claude AI now available to cybersecurity red teams

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical GitHub Copilot CLI Bug Exposes Developer Secrets via Prompt Injection
October 6, 2026
Ex-Engineer Jailed for Sabotaging Employer’s Windows Network
October 6, 2026
Iranian Hackers Target Iraqi Critical Infrastructure With Fake Dubai Airports Coding Test
October 6, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us