Clients of Goldman Sachs’ wealth management division, hedge fund manager Man Group and global property developer Tishman Speyer have been identified among those affected by a significant data breach at EY.
The incident involved unauthorised access to a third-party software platform used by the Big Four audit firm, exposing personal and financial information held in connection with its tax services.
According to reporting by the Financial Times, individuals associated with the three companies received notifications after their information was compromised in the incident, which occurred between 28 March and 12 April 2026.
The disclosures expand the publicly identified group of affected clients several months after EY first notified US regulators of the breach.
Personal and Financial Information Exposed
The attack exploited a vulnerability in software supplied by Checkmarx, a cybersecurity technology provider whose platform was used by EY.
According to breach notifications sent to affected individuals, an unauthorised third party accessed the platform and downloaded documents relating to EY clients.
The exposed information included names, addresses, email addresses, tax identification numbers and financial information.
EY reported the incident to the California Attorney General on 15 July 2026. Notifications were also made to authorities in Texas, Massachusetts and Vermont.
The firm subsequently notified additional affected individuals, including clients of organisations that used EY’s tax services.
Goldman Sachs and Man Group Respond
Goldman Sachs told its wealth management clients that EY had engaged an independent cybersecurity firm to verify that the affected systems were secure.
The bank said its own technology risk team was independently assessing EY’s remediation efforts and seeking evidence that the measures were effective.
Goldman Sachs emphasised that its internal systems had not been compromised and that client assets held by the bank remained safe.
Man Group similarly confirmed that the incident involved third-party software used by EY rather than its own systems.
Tishman Speyer had previously disclosed that information relating to its investors might have been affected. Its internal systems were also not compromised.
EY Faces US Class-Action Litigation
The data breach has also prompted proposed class-action litigation in the United States.
As Big4News reported in July, Illinois resident Markishi Wyatt filed a lawsuit against EY in the US District Court for the Southern District of New York, seeking to represent individuals whose information was compromised.
The complaint alleges that EY failed to implement adequate cybersecurity safeguards to protect sensitive tax, financial and personal information, leaving affected individuals exposed to increased risks of identity theft and financial fraud.
The allegations have not been established in court, and EY has not admitted liability.
Investigation and Remediation
Cybercriminal group ShinyHunters claimed responsibility for the breach in July. The claim has been reported publicly but does not, by itself, establish responsibility for the attack.
EY said it had conducted a comprehensive review of the affected information and was communicating the results directly to clients as its investigation approached completion.
The firm also offered affected individuals credit monitoring and identity protection services.
An EY spokesperson said the incident had not affected the firm’s broader enterprise systems and did not threaten its continuing operations.
The breach highlights the risks associated with sensitive client information processed through third-party technology platforms, particularly for professional services firms handling financial and tax records across multiple organisations.
Trying to keep up with technology at Deloitte, PwC, EY and KPMG? Start here →
https://www.big4news.com/t/technology-and-ai
About the author: Claudine Cassar is the founder and editor of Big4News, covering audit, consulting, regulation and governance across Deloitte, PwC, EY and KPMG.



