Ernst & Young (EY) has told clients that a cyberattack on one of its internal platforms exposed personal and financial details of people connected to Goldman Sachs and Man Group. The Financial Times first reported the widening impact.
Notification letters sent at the end of September say an unauthorized party had access to the platform from March 28 to April 12, 2026, and downloaded documents tied to several EY clients. The exposed data includes names, addresses, email addresses, tax identification numbers and financial details. Those affected include clients of Goldman Sachs' wealth management arm and people linked to the London-listed hedge fund Man Group. Reporting does not say how many individuals are affected.
A support tool, not the banks' systems
The platform was a third-party IT service management tool used by EY staff supporting tax teams. Support tickets on it carried attachments with sensitive client tax documents, so client data sat in a workflow outside clients' own networks.
EY first disclosed the incident in July and blamed a vulnerability in Checkmarx software. Public reporting has not named a specific CVE, software version or attack method, so how the intruder got in remains unclear.
EY noticed unusual activity on April 23, eleven days after the last known unauthorized access. By then, an independent cybersecurity firm found, documents had already been downloaded.
Firms say their own systems were untouched
Goldman Sachs and Man Group both said their systems were not compromised. Goldman said client assets remain safe. In a Sept. 24 letter to clients, Goldman said its technology risk team was reviewing the independent verification of EY's fixes and had asked for objective evidence that those fixes work. Reports attribute that request to Goldman only, not to Man Group.
EY says its wider enterprise systems and business operations were not affected and that its review is nearly complete. It has notified regulators in California, Texas, Massachusetts and Vermont, and is offering affected people credit monitoring and identity protection through a third-party provider.
In its July notice, EY said it had no evidence the data had been misused or that anyone was specifically targeted. That reflected what it knew at the time and does not rule out later misuse.
