VYPR
breachPublished Oct 7, 2026· 1 source

EY Data Breach Exposes Goldman Sachs and Man Group Clients' Sensitive Information

Ernst & Young (EY) has disclosed a data breach impacting clients of Goldman Sachs and Man Group, stemming from a vulnerability in a third-party tax support platform.

Ernst & Young (EY) has alerted clients of major financial firms Goldman Sachs and Man Group that their personal and financial data was exposed due to a cyberattack targeting a platform used for EY's tax services. The breach, which occurred between March 28 and April 12, 2026, compromised sensitive information including names, addresses, tax identification numbers, email addresses, and financial details.

The incident did not directly affect the internal systems of Goldman Sachs or Man Group, but rather a third-party platform that supported EY's tax operations. This platform stored attached documents containing sensitive client tax information within its workflow. EY first became aware of suspicious activity on April 23, 2026, eleven days after the unauthorized access window closed, and subsequently confirmed that documents had been downloaded.

While EY initially attributed the breach to a vulnerability in Checkmarx software, specific details such as the CVE identifier, the exact software version exploited, or the precise method of exploitation remain undisclosed in public reports. This lack of technical detail makes it challenging to fully assess the entry vector and the nature of the vulnerability.

Goldman Sachs confirmed that its own systems were unaffected and client assets remained secure. Similarly, Man Group stated that its systems were not compromised, emphasizing that the incident involved third-party software used by EY. Following the disclosure, Goldman Sachs reportedly requested evidence from EY verifying the effectiveness of implemented security fixes.

EY has reported the incident to data protection regulators in California, Texas, Massachusetts, and Vermont. The company is offering affected individuals credit monitoring and identity protection services. At the time of EY's initial July disclosure, there was no evidence of the exposed data being misused, though this does not preclude future exploitation.

This breach underscores the significant risks associated with data stored in third-party support systems, even when those systems are not directly part of a primary organization's core infrastructure. The compromise highlights how vulnerabilities in ancillary platforms can serve as an indirect pathway to highly sensitive client data.

EY has stated that the incident did not impact its broader enterprise systems or disrupt ongoing business operations. The company's internal review of the incident is reportedly nearing completion, with efforts focused on ensuring the security of its systems and client data moving forward.

The incident serves as a stark reminder for organizations to rigorously vet the security practices of their third-party vendors and to ensure that all systems handling sensitive data, including support platforms, are adequately protected against evolving cyber threats.

Synthesized by Vypr AI