Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > EY Tax Platform Breach Exposes Data Tied to Goldman Sachs and Man Group Clients
EY Tax Platform Breach Exposes Data Tied to Goldman Sachs and Man Group Clients
Read Time:3 Minute, 18 Second

Ernst & Young has notified individuals that an intrusion into a platform supporting its tax services exposed personal and financial information associated with several clients, including Goldman Sachs and Man Group. The incident did not originate inside either financial company’s network, but it still placed their customers’ data in the hands of an unauthorized party.

The disclosure expands the known reach of an event EY first reported in July. According to notices sent in late September, an intruder accessed the affected environment between March 28 and April 12, 2026, and downloaded documents linked to multiple EY clients. The exposed material included names, postal and email addresses, tax identification numbers and financial details.

A support platform became the weak link

The compromised system supported EY teams carrying out tax work. Support tickets could contain attachments with sensitive client tax documents, meaning valuable information sat in an operational workflow outside the networks of the organizations whose customers were affected. An attacker therefore did not need to breach Goldman Sachs or Man Group directly to obtain data connected to their clients.

EY attributed the initial access to a vulnerability in Checkmarx software, although public reporting has not identified a CVE, a vulnerable version or the precise exploitation method. That lack of detail makes it difficult for defenders to map this case to their own environments. It also underlines the importance of obtaining concrete technical evidence from vendors rather than relying only on general assurances.

The timeline leaves another important question. EY detected unusual activity on April 23, eleven days after the reported access window ended. By then, investigators later determined, documents had already been taken. The gap demonstrates why systems used for customer support and professional services need monitoring that is proportionate to the sensitivity of the files they handle.

Financial firms say their own systems were not breached

Goldman Sachs said its infrastructure was unaffected and that client assets remained secure. Man Group likewise described the incident as involving software used by EY, rather than a compromise of Man Group systems. Those distinctions matter: the event is a data exposure involving clients of the financial firms, not evidence that attackers entered their trading or banking platforms.

Goldman Sachs also told clients that EY had hired an independent cybersecurity company to confirm the affected systems were secure. Its technology risk team requested objective evidence and third-party validation that remediation had worked. Public reports do not establish that Man Group made the same demand.

EY said the event did not affect its wider enterprise systems or interrupt operations. It reported the breach to regulators in California, Texas, Massachusetts and Vermont, and offered affected people credit monitoring and identity-protection services. The firm previously said it had found no evidence that the stolen data was misused or that specific individuals were deliberately selected, but an absence of observed misuse is not a guarantee that it will never occur.

What affected people and organizations should do

Tax identifiers and financial details can remain useful to criminals long after a breach. People receiving a legitimate notice should verify it through an official channel, enroll in monitoring if appropriate and treat unexpected messages about investments, tax refunds or account problems with caution. Requests that reference accurate personal details can still be fraudulent.

  • Watch financial and credit reports for unfamiliar activity.
  • Use unique passwords and phishing-resistant multifactor authentication on email and financial accounts.
  • Confirm urgent requests through a known phone number rather than links in messages.
  • Preserve breach notices and document any suspicious activity for banks or regulators.

For enterprises, the lesson is broader than this single product. Data inventories should include ticketing, support and professional-services platforms, not just primary databases. Contracts should set expectations for logging, incident notification and evidence-based remediation. Sensitive attachments should be minimized, encrypted and retained only as long as necessary. A supplier may sit outside the corporate perimeter, but the data it holds remains part of the organization’s exposure.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on EY Tax Platform Breach Exposes Data Tied to Goldman Sachs and Man Group Clients, use the discussion on Forum.

>> forum community

Comments

Leave a Reply