Goldman Sachs and London hedge fund Man Group have been identified as clients affected by a cybersecurity breach at accounting firm Ernst & Young, where an unauthorized third party accessed an IT service-management platform used for EY's tax work. The incident, active from late March to mid-April 2026, exposed personal and financial data including names, addresses, tax identifiers, email addresses, and financial information belonging to affected clients.
Unauthorized access to EY's IT service-management platform used for tax work was active from March 28 to April 12, 2026. EY identified the breach on April 23 and subsequently notified affected clients. Goldman Sachs and Man Group have been reported as among the clients whose data was involved. Goldman Sachs stated publicly that its own internal systems and client assets were not affected. EY has notified U.S. state regulators including California, Texas, Massachusetts, and Vermont. EY is offering credit monitoring to affected individuals. Cybersecurity forensic investigations are ongoing.
For institutional clients and private wealth customers, Goldman Sachs says its own systems were not affected and client assets were not impacted. The compromise was restricted to data held within EY's IT service-management platform. Corporate compliance officers and affected hedge fund partners should prepare for targeted spear-phishing campaigns and review vendor access privileges, as exfiltrated data of this type can be used in social engineering attacks.
What Third-Party Breaches Mean for Financial Firms
The EY incident fits a pattern that has accelerated across professional services in recent years: the target is not the bank itself, but a trusted intermediary that sits between the bank and its clients. EY as a Big Four auditor holds engagement files, project correspondence, and advisory documentation containing sensitive corporate information. That material, once exfiltrated from a support platform, has value for social engineering and business email compromise attacks regardless of whether any trading system was touched.
For compliance teams and enterprise risk officers, the practical next step is auditing which third-party vendors hold copies of your institution's internal correspondence and project files. Standard vendor due diligence often focuses on technology infrastructure; the EY incident demonstrates that IT service management and tax-support platforms carry equivalent exposure.
On whether Goldman Sachs systems were hacked in the EY breach: No. Goldman Sachs' internal networks and client assets were not affected, per Goldman's own public statement. The breach occurred on an EY IT service-management platform used for tax work, which exposed personal and financial data belonging to clients whose information was held in that system.
Ongoing forensic audits and regulatory notifications to U.S. state regulators will determine the final scope of the incident. Further client disclosures are expected as investigations conclude in the coming weeks.
Related coverage: third-party IT platform access incidents; Karmactive cybersecurity coverage. For primary-source context, see CISA third-party risk guidance.
(function () {
var btn = document.getElementById('karmactivePushBtn');
var status = document.getElementById('karmactivePushStatus');
if (!btn) return;
function setStatus(msg) {
if (status) status.textContent = msg;
}
function fallback() {
setStatus('Push notifications are not supported in this browser. Try the email option above.');
}
btn.addEventListener('click', function () {
try {
/* OneSignal v16+ deferred SDK */
if (window.OneSignalDeferred && Array.isArray(window.OneSignalDeferred)) {
setStatus('Opening notification prompt...');
window.OneSignalDeferred.push(function (OneSignal) {
if (OneSignal && OneSignal.Notifications && typeof OneSignal.Notifications.requestPermission === 'function') {
OneSignal.Notifications.requestPermission()
.then(function () {
setStatus('You will receive push notifications when new articles are published.');
})
.catch(fallback);
} else {
fallback();
}
});
return;
}
/* OneSignal direct object */
if (window.OneSignal && OneSignal.Notifications && typeof OneSignal.Notifications.requestPermission === 'function') {
OneSignal.Notifications.requestPermission()
.then(function () {
setStatus('You will receive push notifications when new articles are published.');
})
.catch(fallback);
return;
}
/* Older OneSignal SDK */
if (window.OneSignal && typeof OneSignal.push === 'function') {
setStatus('Opening notification prompt...');
OneSignal.push(function () {
if (typeof OneSignal.showSlidedownPrompt === 'function') {
OneSignal.showSlidedownPrompt();
} else {
fallback();
}
});
return;
}
fallback();
} catch (e) {
fallback();
}
});
})();