In short: Professional services firm Ernst & Young (EY) notified clients of a breach of a third-party support platform used by its tax teams. Attackers accessed the platform between March 28 and April 12, 2026, and downloaded documents containing personal and financial data — names, addresses, tax identification numbers, and account details. Among those affected are clients of Goldman Sachs' wealth management business and the UK-listed hedge fund Man Group. Goldman Sachs' and Man Group's own banking systems were not affected — the breach happened entirely on EY's side.
What happened
EY used a third-party IT service management platform through which internal staff handled support tickets related to client tax work. Those tickets frequently included attachments with sensitive tax documents — a common but risky practice, since support tools often receive less scrutiny than a company's core databases. According to investigators, the flaw was linked to Checkmarx software, and EY didn't detect unusual activity on the platform until April 23 — more than ten days after the last recorded unauthorized access.
The ShinyHunters extortion group later claimed responsibility, saying initial access to EY's infrastructure came through a supply-chain attack using compromised credentials, which it claims gave attackers reach into EY's internal Jira, GitHub, and Azure environments.
What data was exposed
The leaked documents include names, home addresses, tax identification numbers, email addresses, and financial details; for some clients, Social Security numbers and credit/debit account details were also referenced. Goldman Sachs confirmed its own systems were unaffected and that client assets remain safe; Man Group made a similar statement, calling the incident "independent of Man Group's systems." EY is offering affected clients two years of free credit monitoring and identity theft protection.
Why this matters even if you're not a Goldman Sachs client
The EY case is a textbook example of third-party vendor risk: the data leaked not from the bank's own systems but from a support tool run by its auditor, and the gap between unauthorized access and detection exceeded 85 days. It illustrates a broader point — the chain of companies that touch your personal and financial data is usually longer than it looks: your accountant, your auditor, their tax consultants, and each one's IT contractors. The longer that chain, the higher the combined odds that one link turns out to be weak, and the client is usually the last to find out.
We covered a similar pattern recently in our piece on the Microsoft Titan internal-service breach, where the weak point was also a support component rather than the core infrastructure.
What to do if you might be affected
If you're a Goldman Sachs Wealth Management or Man Group client, check for a notification from EY and take advantage of the free credit monitoring offered. More broadly, after any major financial data breach it's worth changing passwords on banking and tax-related accounts, enabling two-factor authentication, staying wary of emails or calls referencing a "breach" that ask you to confirm card details or click a link, and periodically checking your credit report for loan applications opened in your name without your knowledge.
More breach breakdowns like this are on the LiMP VPN blog.
Where a VPN fits in
A VPN can't prevent a breach of a third-party vendor's infrastructure — that happens outside your control and outside your device. But it remains an independent layer of protection for your own network traffic: the LiMP VPN app encrypts your connection and hides your real IP address, reducing the risk of data interception when you access banking and tax services over public Wi-Fi or an unsecured network. A verified no-logs policy, plans from 69 ₽/month — details on the pricing page.
