The EY data breach has exposed sensitive information belonging to clients of Goldman Sachs, Man Group and real estate developer Tishman Speyer. According to the Financial Times, compromised records included names, addresses, email addresses, tax identifiers and financial information. Goldman Sachs and Man Group said their own internal systems were unaffected. EY attributed the incident to a vulnerability involving Checkmarx software.
The intrusion involved a third-party IT service management platform used by EY staff to support client tax work. Support tickets sometimes contained attachments with confidential tax information, giving attackers access to documents beyond routine technical requests. EY’s investigation determined that unauthorized access and document downloads occurred between March 28 and April 12, 2026. The firm detected unusual activity on April 23 and activated its incident response procedures.
EY brought in outside cybersecurity specialists, notified relevant authorities and affected clients, and said it secured the impacted systems. Earlier breach notifications offered affected individuals 24 months of identity monitoring and restoration services through Experian. Those receiving a notification should review it carefully for details about the information involved and available assistance.
The EY breach illustrates how support platforms can become a source of sensitive data exposure when confidential documents are attached to service requests. It also highlights the importance of including third-party systems in security reviews and limiting the information retained in support tickets. For organizations handling tax and financial records, protecting these supporting workflows is an essential part of protecting client information.

