EY breach widens: documents stolen from an IT service-management platform used for tax work (28 Mar to 12 Apr 2026) exposed clients of Goldman Sachs wealth management, Man Group and Tishman Speyer
Notification letters from Ernst & Young LLP (EY), reported by the Financial Times on 6 October 2026, show the firm's spring 2026 breach reached clients of financial firms that use EY's tax services, including Goldman Sachs' wealth management business, UK-listed hedge fund Man Group and property developer Tishman Speyer. EY's letters, dated around 24 September, say EY's IT staff used a third-party IT service-management platform whose tickets could hold documents containing client tax information. An unauthorised third party accessed that platform between 28 March and 12 April 2026 and downloaded documents relating to a number of EY clients; EY confirmed the unusual activity on 23 April. The exposed data includes names, addresses, tax identification numbers, email addresses and financial information about investment holdings. EY first disclosed the incident in July and, according to the FT, linked it to a vulnerability in Checkmarx software; no CVE or version has been named publicly. Goldman Sachs and Man Group say their own systems were not affected, and Goldman told clients it had asked EY for objective, independently checked evidence that its fixes work. EY has notified US federal law enforcement and several state regulators and is offering credit monitoring. The number of people affected has not been published. Primary: Financial Times; wire: Cyber Security News.
- Product
- EY third-party IT service-management platform (tax services support tickets)
- Versions
- n/a — incident
- Exploited in Australia?
- unknown
- Patch to
- Affected clients: use the credit monitoring EY is offering, consider a credit freeze or fraud alert, and expect targeted phishing that quotes real tax or holdings details. Organisations: treat service desk and ticketing platforms as stores of sensitive data, keep client documents out of support tickets or purge attachments on a schedule, and ask advisers and other service providers for evidence of how they protect your clients' data.
Primary: Financial Times — Goldman Sachs and Man Group exposed in EY data breach (6 Oct 2026) · Cyber Security News — EY Data Breach Exposes Goldman Sachs and Man Group Clients' Data (7 Oct 2026)
