Ernst & Young (EY) has confirmed that an unauthorised party got into a third-party IT support platform used by its tax teams and downloaded documents belonging to several clients. Notification letters sent at the end of September 2026 show that the affected people include clients of Goldman Sachs' wealth management business and the UK-listed hedge fund Man Group. Tishman Speyer has also been reported among the affected organisations, according to Financial Times reporting summarised by several outlets. The intrusion ran from late March to mid-April 2026, and EY first disclosed it in July. EY has not said how many people were affected. VicyTech counts at least 1,366 US residents across just four state filings, while breach indexer DataBreach.com says it has catalogued about 1.2 million records tied to a leak attributed to the ShinyHunters extortion group. EY has not confirmed that ShinyHunters was involved.
What Happened
Most sources, citing EY's notification letters, put unauthorised access to the platform between March 28 and April 12, 2026. Tech-Insider notes that CFO.com, reporting on EY's own notice, gives a slightly earlier start date of March 26. EY detected unusual activity on April 23, eleven days after the last recorded access. It then hired an independent cybersecurity firm, whose investigation found that documents had already been downloaded during the access window.
The disclosure has come out in stages:
- Mid-July 2026: EY disclosed the incident and filed notifications with state attorneys general, including in California and Texas (DataBreach.com). At that point EY described the impact only as affecting "a number of EY clients."
- July 20, 2026: A proposed class action, Wyatt v. Ernst & Young LLP (Case No. 1:26-cv-06108), was filed in the US District Court for the Southern District of New York. No class has been certified and there is no settlement (All About Lawyer, DataBreach.com).
- July 27, 2026: ShinyHunters reportedly added EY to its leak site. It claimed it got credentials through a supply-chain compromise and set a July 31 deadline. DataBreach.com, citing BleepingComputer, says the data was published after the deadline passed.
- Late September 2026: Letters reached individuals linked to Goldman Sachs and Man Group. Cyber Insider reports a Massachusetts filing made on behalf of Man Group, which confirms that EY held information about investment holdings while doing tax work for the asset manager and its affiliates.
The networks of Goldman Sachs and Man Group were not breached. An EY spokesperson told City AM that the incident "did not impact broader EY enterprise systems," that the investigation "is now in its final stages," and that results are being shared directly with clients.
What Was Taken
EY's notifications, as quoted by Cyber Security News, City AM and All About Lawyer, list these exposed data types: names, postal addresses, email addresses, tax identification numbers and financial details. Cyber Insider stresses that exposure differs by client and by individual, so the data should not be treated as one uniform dataset.
DataBreach.com describes a different set of six fields in the dataset it has indexed:
- Email addresses: 1,205,607 records
- Phone numbers: 704,241
- Names: 394,042
- Street addresses: 236,825
- Dates of birth: 65,445
- Social Security numbers: 11,611
The estimates of scale vary widely and none is authoritative. EY has not published a total. VicyTech counts at least 1,366 US residents across four state filings and says the real figure is undisclosed. The roughly 1.2 million figure from DataBreach.com counts rows in a leak that the site links to a claim EY has not verified. It counts records, not unique people, and should be read as an upper bound. Tax IDs and financial records belonging to high-net-worth wealth clients are valuable for targeted fraud, impersonation and social engineering, regardless of the final headcount.
Why It Matters
This is a fourth-party exposure. Goldman Sachs and Man Group lost data without any failure in their own environments. The data went out through their auditor's tax function, and then through the auditor's IT support vendor. Sensitive client tax documents had been attached to internal helpdesk tickets. That is an ordinary practice, but it puts regulated financial data inside a system that is rarely classified, monitored or governed as a data store.
Detection is the second concern. Darktrace's Nathaniel Jones told City AM that "document theft often looks like normal business activity." Bulk downloads through a legitimate SaaS session do not trip malware or exploit-focused controls. The eleven-day gap between the last access and detection, and the months-long gap before individuals were notified, show how long these exposures can stay invisible to the people whose data is involved.
The Attack Technique
The entry point is the least settled part of the story.
- Checkmarx vulnerability: The Australian Financial Review (FT syndication) reports that EY attributed the incident to a vulnerability in Checkmarx software that affected EY, several clients and many other organisations. Cyber Security News says no CVE, affected version or exploit method has been identified.
- Unnamed ITSM vendor: Tech-Insider and VicyTech say EY has not publicly named the compromised platform vendor. This sits awkwardly with the Checkmarx attribution, and it is unclear whether Checkmarx was the ITSM platform itself or an upstream link in the chain.
- Credential theft via supply chain: ShinyHunters claims it obtained credentials through a supply-chain compromise (via BleepingComputer, per DataBreach.com). The claim is unverified, but it fits the group's known pattern of abusing SaaS credentials to bulk-exfiltrate data.
Accounts differ. The confirmed facts are unauthorised access to a third-party ITSM platform and the download of ticket attachments. The specific vulnerability, the vendor and the actor are all unconfirmed by EY.
What Organizations Should Do
- Map fourth-party data flows. Ask auditors, tax advisers and law firms where your documents end up, including the helpdesk, ticketing and collaboration tools they use. Write data-handling terms into engagement contracts.
- Treat ITSM and ticketing systems as sensitive data stores. Block or automatically purge regulated attachments such as tax IDs, SSNs and financial statements. Apply DLP scanning and retention limits to ticket content.
- Baseline and alert on bulk download behaviour in SaaS. Watch for unusual volumes of attachment or API retrieval, new IP addresses or ASNs, and off-hours sessions. Assume theft will look like normal use.
- Harden SaaS credentials and integrations. Require phishing-resistant MFA, restrict OAuth and API tokens, rotate service credentials, and review third-party app connections. These are the paths ShinyHunters-style operations exploit.
- Prepare affected individuals for targeted fraud. Expect tax-ID-driven phishing and impersonation aimed at wealth clients. Point people to the 24 months of identity monitoring EY is offering (enrolment reportedly closes October 31, 2026) and to credit freezes.
- Shorten the path from detection to notification. Pre-agree incident notification SLAs with service providers so clients are not left waiting months to learn what was exposed.
Sources: EY Breach Exposes 6 Data Types, Goldman Sachs Hit | EY data breach victims include Goldman Sachs and Man Group clients... | EY breach exposes financial data held for major clients > Cyber Ins... | Goldman-linked EY breach highlights new era of undetectable ... | Ernst & Young Search the Data Breach | EY Data Breach Exposes Goldman Sachs and Man Group ... | EY Data Breach Explained: How Goldman Sachs, Man Group and Tishman... | EY Data Breach, Goldman Sachs, Man Group Clients Exposed