EY Data Breach Involves Goldman Sachs and Man Group Client Data, but Goldman Says Its Systems Were Unaffected

October 8, 2026
3 mins read
Rows of dark server racks in a bright data-centre aisle
Illustrative cybersecurity image. [Source: Ourspeed]

Goldman Sachs and London hedge fund Man Group have been identified as clients affected by a cybersecurity breach at accounting firm Ernst & Young, where an unauthorized third party accessed an IT service-management platform used for EY's tax work. The incident, active from late March to mid-April 2026, exposed personal and financial data including names, addresses, tax identifiers, email addresses, and financial information belonging to affected clients.

Unauthorized access to EY's IT service-management platform used for tax work was active from March 28 to April 12, 2026. EY identified the breach on April 23 and subsequently notified affected clients. Goldman Sachs and Man Group have been reported as among the clients whose data was involved. Goldman Sachs stated publicly that its own internal systems and client assets were not affected. EY has notified U.S. state regulators including California, Texas, Massachusetts, and Vermont. EY is offering credit monitoring to affected individuals. Cybersecurity forensic investigations are ongoing.

For institutional clients and private wealth customers, Goldman Sachs says its own systems were not affected and client assets were not impacted. The compromise was restricted to data held within EY's IT service-management platform. Corporate compliance officers and affected hedge fund partners should prepare for targeted spear-phishing campaigns and review vendor access privileges, as exfiltrated data of this type can be used in social engineering attacks.

What Third-Party Breaches Mean for Financial Firms

The EY incident fits a pattern that has accelerated across professional services in recent years: the target is not the bank itself, but a trusted intermediary that sits between the bank and its clients. EY as a Big Four auditor holds engagement files, project correspondence, and advisory documentation containing sensitive corporate information. That material, once exfiltrated from a support platform, has value for social engineering and business email compromise attacks regardless of whether any trading system was touched.

For compliance teams and enterprise risk officers, the practical next step is auditing which third-party vendors hold copies of your institution's internal correspondence and project files. Standard vendor due diligence often focuses on technology infrastructure; the EY incident demonstrates that IT service management and tax-support platforms carry equivalent exposure.

On whether Goldman Sachs systems were hacked in the EY breach: No. Goldman Sachs' internal networks and client assets were not affected, per Goldman's own public statement. The breach occurred on an EY IT service-management platform used for tax work, which exposed personal and financial data belonging to clients whose information was held in that system.

Ongoing forensic audits and regulatory notifications to U.S. state regulators will determine the final scope of the incident. Further client disclosures are expected as investigations conclude in the coming weeks.

Related coverage: third-party IT platform access incidents; Karmactive cybersecurity coverage. For primary-source context, see CISA third-party risk guidance.

Sunita Somvanshi

With over two decades of dedicated service in the state environmental ministry, this seasoned professional has cultivated a discerning perspective on the intricate interplay between environmental considerations and diverse industries. Sunita is armed with a keen eye for pivotal details, her extensive experience uniquely positions her to offer insightful commentary on topics ranging from business sustainability and global trade's environmental impact to fostering partnerships, optimizing freight and transport for ecological efficiency, and delving into the realms of thermal management, logistics, carbon credits, and energy transition. Through her writing, she not only imparts valuable knowledge but also provides a nuanced understanding of how businesses can harmonize with environmental imperatives, making her a crucial voice in the discourse on sustainable practices and the future of industry.

Leave a Reply

Your email address will not be published.

Laptop computer and stethoscope representing digital health data management in hospitals.
Previous Story

NHS Palantir Data Objection: What GDPR Article 21 Allows

Lane Johnson in a pre-snap stance for the Philadelphia Eagles
Next Story

Eagles’ Lane Johnson Retires Mid-Season After 14 Years and Two Super Bowl Titles

Latest from Business

A corporate office building with modern architecture.

HubSpot Cuts 660 Jobs: AI Strategy and Severance

Cambridge-based marketing software company HubSpot will cut approximately 660 roles—roughly 7 percent of its global workforce—under a restructuring plan announced in an internal message from CEO Yamini Rangan and disclosed in a
An oil pump jack operating at an oil field in California.

Oil Prices Rise: Why Brent Topped $100

Brent crude crossed $100 per barrel on Wednesday after Houthi drone and missile strikes targeted Saudi infrastructure, prompting a sharp repricing of regional supply risks. Saudi Aramco has not confirmed the operational

Don't Miss

Laptop computer and stethoscope representing digital health data management in hospitals.

NHS Palantir Data Objection: What GDPR Article 21 Allows

NHS patients in England have a specific legal