Data breaches

EY: data linked to Goldman Sachs and Man Group exposed

An intrusion at an EY tax-services platform in spring 2026 exposed financial client information; further details emerged in October.

Conceptual illustration: EY: data linked to Goldman Sachs and Man Group exposed
Conceptual illustration · SecurCheck

What is confirmed

Early October reporting says documents accessed or copied during an EY intrusion contained information linked to Goldman Sachs Wealth Management and Man Group clients.

Notices place unauthorised access between March 28 and April 12, 2026. Reported categories include names, contact details, tax identifiers and certain financial information.

Goldman Sachs and Man Group said their own systems were not compromised. The incident affected an environment operated by service provider EY.

What it means

Centralised tax-related documents at a service provider can create exposure for many client organisations.

Exposure of financial information does not prove access to bank accounts or misappropriation of assets.

How the incident unfolded

Early October reporting says documents accessed or copied during an EY intrusion contained information linked to Goldman Sachs Wealth Management and Man Group clients.

Notices place unauthorised access between March 28 and April 12, 2026. Reported categories include names, contact details, tax identifiers and certain financial information.

What it means for affected people

Centralised tax-related documents at a service provider can create exposure for many client organisations.

Exposure of financial information does not prove access to bank accounts or misappropriation of assets.

Practical safeguards

Review notices directly from EY or your financial institution without following unexpected links.

Be alert for impersonation emails using correct tax references or personal information.

What to do

Review notices directly from EY or your financial institution without following unexpected links.

Be alert for impersonation emails using correct tax references or personal information.

Organisations should map data entrusted to service providers and limit retention periods.

Check a suspicious sign

Use the related SecurCheck tool, then confirm important decisions with an official source.

Sources

  1. Financial Times — 7 octobre 2026
  2. ECO — 7 octobre 2026