EY Data Breach Exposed Goldman Sachs Client Records
A security vulnerability in third-party software led to the unauthorized access of sensitive financial client data.
Updated on Oct. 7, 2026 in Cybersecurity

Live Poll
Do you trust large companies to keep your personal data secure from third-party vendor breaches?
An unauthorized party accessed an Ernst & Young tax services platform between March 28 and April 12, 2026, compromising sensitive information belonging to clients of Goldman Sachs and Man Group. EY disclosed the incident in July 2026 after detecting unusual system activity.
Why it matters
The breach highlights the risks posed by vulnerabilities in third-party software management tools, which can serve as entry points to sensitive financial data. While the firm's internal systems remained secure, the incident impacted the data security of major institutional clients.
The unauthorized access was traced to a vulnerability within Checkmarx software utilized on an IT service management platform. Exposed data fields included names, addresses, tax identification numbers, and email addresses.
The players
Ernst & Young
Ernst & Young is a global professional services firm that provides assurance, tax, transaction, and advisory services to various large-scale institutional clients.
Goldman Sachs
Goldman Sachs is a leading global investment banking, securities, and investment management firm that serves a diverse client base.
Man Group
Man Group is an active investment management business that provides a range of investment products and solutions.
Checkmarx
Checkmarx is a software security company that provides application security testing solutions used by organizations to identify vulnerabilities in their code.
The details
Unauthorized parties successfully downloaded documents from an IT service management platform used for tax support tickets. EY confirmed that the internal systems at both Goldman Sachs and Man Group remained uncompromised throughout the incident.
Timeline
March 28, 2026 - April 12, 2026: Unauthorized party accessed the EY platform.
April 23, 2026: EY detected unusual activity on its systems.
July 2026: EY publicly disclosed the security incident.
September 24, 2026: Goldman Sachs notified its clients regarding the breach.
The Tech Race
The incident highlights how reliance on third-party IT management platforms has become a critical vector in the evolving landscape of enterprise cybersecurity. As firms increasingly centralize services, a single vulnerability in tools like Checkmarx can create significant exposure across multiple institutional partners.
Affected individuals are being offered credit monitoring and identity protection services to mitigate potential fraud risks resulting from the exposure of their tax and financial information. Clients should remain vigilant for phishing attempts that leverage the stolen contact details.
The takeaway
This event serves as a reminder that individual data security is often tied to the resilience of third-party vendors used by major financial institutions. Consumers should proactively monitor their accounts and take advantage of identity protection services when notified of such breaches.
Further reading
For more information on how firms manage data security risks, visit the Cybersecurity section.
Source note: This article includes information reported by Cyber Security News.
Live Poll
Do you trust large companies to keep your personal data secure from third-party vendor breaches?










