Ernst & Young’s tax-services platform was compromised between March 28 and April 12, 2026, and the attacker took names, tax IDs, and financial details belonging to clients tied to Goldman Sachs and Man Group. This analysis covers the timeline, the Checkmarx link, the regulatory filings, and what the incident says about third-party risk in financial services.
The breach at a glance
EY, one of the Big Four accounting firms, has confirmed that an intrusion into a platform supporting its tax-services operations exposed sensitive data belonging to individuals associated with Goldman Sachs’ wealth management division and the London-listed hedge fund Man Group. The unauthorized access lasted roughly two weeks and resulted in the exfiltration of documents containing names, residential addresses, tax identification numbers, email addresses, and detailed financial information.
The Financial Times first reported the Goldman and Man Group exposure, and regulatory filings in four U.S. states back it up. It widens an incident EY first disclosed in July 2026. Neither Goldman Sachs nor Man Group had its own internal systems compromised. The attack went only through a third-party IT service management (ITSM) platform that EY’s teams used to process tax-related support tickets, and those tickets carried attachments full of confidential client tax documentation.
Timeline of the EY breach
March 28, 2026: An unidentified threat actor gets into the third-party ITSM platform EY used for internal tax-services support. Nobody has publicly described the initial-access technique, though EY’s July disclosure attributed the intrusion to a vulnerability in Checkmarx software.
April 12, 2026: The last recorded unauthorized activity on the platform. Over the preceding 16 days the attacker downloaded documents tied to multiple EY clients, including those serviced under Goldman Sachs’ wealth management umbrella and Man Group’s operational relationships.
April 23, 2026: EY’s security monitoring flags unusual activity, eleven days after the attacker’s last access. By then the exfiltration was over.
Late April to June 2026: EY brings in an independent cybersecurity firm for a forensic review of the platform. Investigators confirm that documents were downloaded during the March and April window and start scoping the affected clients.
July 2026: EY discloses the breach publicly and blames a vulnerability in Checkmarx software. At that stage the firm says it found no evidence of data misuse or of targeted selection of individuals.
September 24, 2026: Goldman Sachs mails letters to potentially affected wealth management clients. EY files breach notifications with regulators in California, Texas, Massachusetts, and Vermont, and Man Group is notified through parallel channels.
October 2026: The Financial Times publishes its investigation and confirms that data tied to both Goldman Sachs and Man Group was among the exfiltrated material.
📬 Stay Ahead of Cyber Threats
Get the latest cybersecurity news, critical vulnerabilities, threat intelligence, tutorials, and exclusive giveaways delivered straight to your inbox. No spam. Unsubscribe anytime.
Subscribe to the Newsletter →The technical entry point: Checkmarx and the support-platform attack surface
EY’s July disclosure named a vulnerability in Checkmarx software as the root cause. Checkmarx is an Israeli-headquartered application security company whose static analysis (SAST), software composition analysis (SCA), and interactive analysis (IAST) tools sit in CI/CD pipelines at thousands of enterprises. In 2020 it suffered a significant supply-chain compromise, when attackers exploited a flaw in its CxSAST product to push malware through the update mechanism to downstream customers.
Public reporting on the EY case does not give a CVE identifier, the affected Checkmarx product or version, or the exploit chain. Without those details we cannot verify the technical story independently. A few points are still worth knowing.
Checkmarx has appeared in serious CVE disclosures before. CVE-2020-11352 (CVSS 9.8) was a deserialization flaw in CxSAST that allowed remote code execution, and advisories in 2024 and 2025 flagged authentication bypass and path-traversal issues in Checkmarx SCA components. Whether the EY incident maps to a known CVE or to an undisclosed zero-day is unconfirmed.
The compromised system was a third-party ITSM platform, not Checkmarx’s code-scanning engine. EY’s internal tax teams used it to log, track, and resolve support tickets. Checkmarx software was reportedly integrated into or adjacent to that platform’s workflow, which would have given the attacker a bridge from the development-security tooling layer to the operational support layer. The reporting does not describe how that bridge worked.
The support tickets themselves held attachments with sensitive client tax information. Routing client-identifiable tax documents through a ticketing system, instead of keeping them in a hardened document-management environment, widened the attack surface. Whoever compromised the ITSM platform got the financial documents attached to the tickets along with the ticket metadata.
The attacker never had to reach Goldman Sachs’ trading infrastructure or Man Group’s portfolio-management systems. Reaching the intermediary layer where EY handled tax paperwork for those clients was enough.
What data was exposed
The compromised records included full legal names, residential and mailing addresses, email addresses, tax identification numbers (Social Security numbers for U.S. individuals, equivalent national tax IDs for others), and financial details such as account information, income figures, and tax-related disclosures.
Tax IDs combined with names, addresses, and financial specifics make a dangerous dataset. A credit card number can be cancelled and reissued, but a tax identification number is effectively permanent. In the United States, a Social Security number paired with a date of birth and address supports synthetic identity fraud, tax-return fraud, account takeovers, and social-engineering campaigns aimed at wealthy individuals.
The affected population includes clients of Goldman Sachs’ wealth management arm and of Man Group, which manages roughly $178 billion in assets as of mid-2026. These are not retail banking customers. Many are ultra-high-net-worth individuals, institutional investors, fund principals, and corporate officers, and their financial profiles are worth far more to criminal groups and nation-state actors than an ordinary customer’s.
Neither Goldman Sachs nor EY has published the number of people affected. Many breach-notification regimes let firms withhold exact counts during an active investigation, but the eventual figure will shape regulatory scrutiny and class-action exposure.
Goldman Sachs and Man Group: downstream impact, not direct compromise
Both firms moved quickly to mark the boundaries of the incident. Goldman Sachs said its own systems were unaffected and client assets remained secure. Man Group said the incident involved third-party software used by EY and that none of its systems were breached.
Both statements are technically accurate, but the clients’ data was still exposed, and the risk to those individuals is the same whether it leaked from a bank’s servers or an intermediary’s platform. Under the EU’s GDPR, the UK’s Data Protection Act 2018, and various U.S. state privacy laws, the entity that decided the purposes and means of processing bears primary accountability for safeguarding the data. Here that is arguably EY, as the tax-services provider.
Goldman Sachs’ September 24 client letter added that its technology risk team was independently reviewing the remediation done by the cybersecurity firm EY hired. Goldman asked for “objective evidence and third-party checks” that EY’s fixes worked. A major financial institution auditing its service provider’s incident response, instead of taking assurances at face value, is a meaningful governance signal.
Available reporting does not say whether Man Group made the same request. Its operational-risk protocols would normally call for one.
Regulatory notifications and legal obligations
EY filed breach notifications with regulators in at least four U.S. states, and each has its own requirements.
- California (Cal. Civ. Code § 1798.82): Notice goes to affected residents. For breaches involving more than 500 California residents, a sample notification must also go to the California Attorney General. The CCPA/CPRA framework gives individuals a private right of action in certain circumstances.
- Texas (Tex. Bus. & Com. Code § 521.053): Notification is due within 60 days of determining that a breach occurred, and the Attorney General must be told if more than 250 Texas residents are affected.
- Massachusetts (M.G.L. c. 93H and 201 CMR 17.00): Written notice goes to affected residents, the Attorney General, and the Office of Consumer Affairs and Business Regulation. The state’s data-security regulations are among the most prescriptive in the country and require specific technical safeguards from covered entities.
- Vermont (9 V.S.A. § 2435): The Attorney General must be notified within 14 business days of discovery and consumers within 45 days.
EY is also offering affected individuals credit monitoring and identity protection through a third-party provider. That is standard, but security researchers often point out that it falls short on its own when tax identification numbers are involved, because identity-fraud risk lasts for years.
For UK-based individuals linked to Man Group, the Information Commissioner’s Office would normally expect notification under UK GDPR Article 33 within 72 hours of the organization becoming aware of a personal-data breach, unless the breach is unlikely to risk individuals’ rights and freedoms. Public reporting has not confirmed whether EY or Man Group filed with the ICO.
The third-party risk problem
The EY breach follows a long run of compromises that exploited the gaps between organizations and their vendors and software suppliers.
- SolarWinds (2020): Russian state-sponsored actors compromised the software build pipeline of a network-management vendor and reached thousands of downstream organizations, including U.S. government agencies.
- Kaseya VSA (2021): The REvil ransomware gang exploited zero-day vulnerabilities in Kaseya’s remote-management platform and deployed ransomware to roughly 1,500 businesses through managed service providers.
- MOVEit Transfer (2023): The Cl0p ransomware group exploited a SQL-injection vulnerability in Progress Software’s file-transfer application, affecting more than 2,700 organizations and over 90 million individuals.
- Change Healthcare / UnitedHealth (2024): The ALPHV/BlackCat ransomware group breached a healthcare-payments intermediary and disrupted pharmacy and insurance operations across the United States.
- EY / Checkmarx-linked platform (2026): An attacker used a vulnerability in security tooling adjacent to a support platform to exfiltrate tax documents belonging to clients of major financial institutions.
Each case has the same architecture problem. Sensitive data flows through intermediary systems that were never meant to be primary repositories, and they accumulate it anyway as a side effect of daily workflows. Support tickets carry attachments, file-transfer portals hold documents, and ITSM platforms log correspondence that includes account details. These shadow data stores inherit the sensitivity of what they hold, but they often lack the encryption at rest, access segmentation, and exfiltration-tuned anomaly detection that the system of record would enforce.
EY’s platform fits that pattern. Tax documents attached to support tickets sat inside a workflow environment open to IT support staff, and so to anyone who could compromise the platform’s access controls. The Checkmarx vulnerability gave the attacker a foothold, and the decision to route client tax data through that platform set the size of the damage.
Detection gaps and the 11-day blind spot
EY detected anomalous activity on April 23, eleven days after the last unauthorized access on April 12. For those eleven days the exfiltrated data was presumably already in the attacker’s hands, and EY’s security operations had not yet flagged the intrusion.
EY has not described its detection methodology, so the reasons are open. ITSM platforms generate a lot of legitimate traffic, and an attacker who pulled documents gradually, in patterns that looked like normal ticket downloads, might never have tripped a volume-based alert. If the platform shared network segments with other EY systems, lateral-movement signals could have been lost in a broad alerting surface. Data loss prevention tools can detect and block bulk downloads of documents containing PII or financial identifiers, so missing or misconfigured DLP on this platform would have left the exfiltration unflagged. And if the platform’s access logs did not feed a central SIEM with correlation rules for the tax-services workflow, the downloads could have passed as routine.
For organizations reading this as a lesson: detection has to match the sensitivity of the data a system holds, not the system’s job title. A “support platform” that stores tax identification numbers and financial records is a high-value data repository and needs monitoring to match.
What affected individuals should do now
If you received a notification letter from Goldman Sachs, Man Group, or EY about this incident, security professionals recommend these steps.
- Enroll in the credit monitoring and identity protection service on offer, but treat it as a baseline. Tax-ID-based fraud can surface months or years after exposure.
- If you are a U.S. resident, place a fraud alert or credit freeze with Equifax, Experian, and TransUnion. A freeze stops new accounts from being opened in your name without your authorization.
- If your Social Security number was exposed, get an IRS Identity Protection PIN. It adds a second authentication factor to electronic tax filings and makes fraudulent returns much harder to file.
- Watch your financial accounts and tax transcripts. The IRS lets taxpayers request account transcripts at irs.gov to confirm that no fraudulent filings exist.
- Expect targeted phishing. Attackers holding your name, address, email, and financial details can write convincing spear-phishing messages posing as Goldman Sachs, Man Group, EY, or a tax authority. Do not click links or open attachments in unsolicited emails that mention this breach. Contact the institution through verified channels.
- If you are in the UK, consider registering with CIFAS for protective registration, and monitor your credit file through Experian, Equifax, or TransUnion UK.
EY’s response and remediation
EY says the incident did not affect its broader enterprise systems or threaten ongoing business operations, and that its internal review was nearing completion in late September 2026. It engaged an independent cybersecurity firm to run the forensic investigation and verify that the affected systems had been secured.
Goldman Sachs’ independent review of that remediation fits a wider shift in how financial institutions handle vendor risk. Under the SEC’s cybersecurity disclosure rules (effective December 2023) and the operational-resilience expectations of frameworks such as the Basel Committee’s principles and the UK FCA and PRA guidelines, institutions are increasingly expected to show active oversight of third-party providers, and contractual compliance alone no longer covers that.
EY’s July statement that it had “no evidence” of data misuse or targeted individual selection describes what forensics showed at that point. It is not a guarantee about the future. Data exfiltrated in March could still be sold on underground forums or used in social-engineering campaigns long after the initial investigation closes.
Broader implications for financial and professional-services firms
Regulation is tightening. The SEC’s disclosure rules, the EU’s Digital Operational Resilience Act (DORA, fully in effect since January 2025), and the UK’s forthcoming operational-resilience regime all require financial institutions to assess, monitor, and report on the cyber resilience of their critical third-party providers. EY, as a tax-services provider to major financial firms, falls squarely inside that scope.
The Big Four (Deloitte, PwC, EY, and KPMG) process an enormous volume of sensitive corporate and individual financial data, so a breach at any one of them has systemic reach. The EY incident will likely speed up internal security reviews at the other three and push clients to revisit their data-handling agreements.
The attack surface of a financial institution includes every vendor, platform, and software component that touches client data, whether or not it sits inside the institution’s own network. Defenders have long known this, but governance structures rarely encode it.
If the exploited vulnerability is confirmed to be in a Checkmarx product, application-security tooling will come under fresh scrutiny as an attack vector. Security tools sit close to source code, build pipelines, and development infrastructure, so compromising one can open a path into the operational environments it was meant to protect.
What remains unknown
- The specific CVE or vulnerability exploited. Without an identifier, researchers cannot map the flaw to a known technique, check whether a patch existed before the attack, or tell whether it was a zero-day.
- The identity and motive of the threat actor. Nobody has made a public attribution. Targeting tax data of high-net-worth individuals could point to financially motivated crime, state-sponsored collection, or hacktivism, and the answer changes the risk for affected people.
- The number of affected individuals. EY, Goldman Sachs, and Man Group have not published a figure, which bears on regulatory penalties, litigation exposure, and the scale of remedial services.
- Whether the exfiltrated data has appeared on underground forums or in later fraud campaigns. EY’s July statement covered the absence of misuse at that time, but the monitoring window for tax-related identity fraud spans several filing seasons.
- Whether Man Group independently audited EY’s remediation, as Goldman Sachs did.
Final analysis
The Checkmarx vulnerability was the way in. The decision to route client tax documents through a support-ticketing workflow determined how much data sat behind that door, and it is the part of this story other firms can check against their own systems today.
For Goldman Sachs and Man Group, the immediate operational impact looks contained: neither firm’s systems were breached and client assets were not directly threatened. For the individuals whose tax identification numbers, addresses, and financial details were taken, the risk is personal, long-lasting, and hard to fully remediate.
Third-party risk is an exploitable attack surface that needs continuous technical verification. Annual questionnaires and compliance checkboxes do not provide it. Goldman Sachs’ insistence on reviewing EY’s remediation evidence independently is the right posture for any organization that relies on third parties to process sensitive data.
We will update this article as new information emerges, including any CVE assignment, threat-actor attribution, or additional regulatory filings.
If you are an EY, Goldman Sachs, or Man Group client and have not received a notification but think you may be affected, contact the institution’s client-services team using contact details from its official website. Do not rely on links or phone numbers in unsolicited emails.









