The Financial Times reports EY's breach has reached clients of Goldman Sachs and Man Group: emails, tax IDs and financial details taken from an IT support ticket queue. I run AliasFleet, an email-alias service built on one address per site, so a leak at a company you never dealt with stays fenced to that one relationship. That is the lens I read this through, and it is the lens that makes this story ugly: none of these victims ever gave anything to EY.
What the Financial Times reported
The new reporting, via Cyber Security News and carried by IT Security News, says notification letters sent at the end of September widened the known impact of an incident EY first disclosed in July:
| Detail | What the letters say |
|---|---|
| Who was breached | Ernst & Young, on a platform used to support its tax services |
| New victims named | Clients of Goldman Sachs' wealth management business and UK-listed Man Group |
| Access window | March 28 to April 12, 2026 |
| Detected | April 23, 2026, eleven days after the last reported access |
| What was taken | Names, addresses, tax identification numbers, email addresses, and financial details |
| How many | Not established for Goldman or Man Group; EY never disclosed a total |
| Firm responses | Goldman says its systems are unaffected and client assets remain safe; Man Group says its systems were not compromised |
The earlier July reporting put more detail on the same incident: notification letters dated July 13 said the exposed data included Social Security numbers, dates of birth and driver's license numbers alongside the email addresses and phone numbers. State filings at the time listed at least 873 Texas residents, 480 in Massachusetts and 13 in Vermont. That floor of 1,366 belongs to the underlying incident, not to the Goldman and Man Group development; do not mix the two numbers.
How a support ticket queue became a tax file
Read the July detail and the mechanism is plain. EY lost a third-party IT service management platform, not a tax system: the place where its own IT staff filed support tickets. Those tickets routinely carried attachments with clients' tax documents. Tax records, sitting in a helpdesk queue.
The intruder spent roughly two weeks inside that queue, downloading documents. EY noticed on April 23, after the access had already stopped. It brought in an outside cybersecurity firm, filed breach notifications with state attorneys general in California, Texas, Massachusetts and Vermont, and started mailing affected people in July.
One more honesty note on attribution. A group calling itself ShinyHunters claimed the breach in July, posting a ransom deadline on a dark-web leak site. That is a claim, not a finding: no authority or company has confirmed it, so the intruder's identity is still unknown. Earlier reporting also pointed at a Checkmarx software vulnerability as the entry point, but the current reporting finds no specific CVE, version, or exploit method attached to that claim. Report it as reported, not as settled.
The victims never signed up with EY
Here is the part that matters for your inbox. A lot of the people whose data was in that queue probably never had a relationship with EY at all. EY does tax work for financial institutions, and the institutions hand EY their clients' documents. Your bank gives EY your tax records, EY drops them into an IT support ticket, a stranger downloads the ticket queue, and now your email address, your tax ID and your financial details are in a corpus somewhere. You were never consulted. There was no consent screen. You simply bank somewhere that outsources its tax work.
This is how modern data handling actually works. Your email address leaves your hands at signup, and from there it moves through vendors, processors, support platforms and contractors, each with its own security standards and its own blind spots. The original company can have perfect security and your address still ends up in someone else's helpdesk.
The people named in the September letters are wealth management and hedge fund clients: exactly the profile spear phishers prize. The stolen data includes email addresses, names and financial details, which is everything a "tax document update" or "account review" lure needs to sound real. Goldman and Man Group both say their systems were not compromised, which is precisely why attackers impersonate the firms by email instead. Any message about this incident should be verified by calling the firm on a number you already trust, never by replying or clicking through.
Goldman's own letter of September 24 shows how little control the victims have over this: the bank told clients it was reviewing EY's fixes and demanding objective evidence that they work. If Goldman Sachs has to ask its vendor to prove the locks are fixed, your ability to influence how your data is stored is zero. The only thing you control is what address you handed out in the first place.
If your data was in EY's queue
Goldman wrote directly to affected clients in September, and EY is offering credit monitoring and identity protection. Work from those contacts first. Then:
- Assume the email address the institutions hold is now a known-live address. It pairs with your name, your tax ID and financial details in someone's file. Treat any unexpected message referencing your tax affairs as hostile until proven otherwise.
- Do not click links in any message claiming to be from Goldman Sachs, Man Group, or EY about this incident. Open the firms' official sites or call numbers you already have.
- Watch for the specific lures this data enables: fake tax document updates, account review requests, and "secure message" prompts referencing wealth management. The combination of name plus financial details is what makes them convincing.
- Check whether the address is already circulating from an earlier leak at Have I Been Pwned. Tax data changes the stakes: a phisher who knows your address is live at a financial institution does not send a generic lure, they send a tax document.
- The rest is mechanical. The breach-response guide lays it out in order.
The address is the only thing you controlled
There is a direct line from this incident to the way aliases work. If the address you gave your bank is your real inbox address, then every vendor your bank shares it with holds a direct line to you, and every vendor's breach becomes your problem. EY's queue is the proof: the leak was not your bank's systems and not EY's core systems, it was a helpdesk, two vendors removed from you.
Hand your bank its own alias and the blast radius shrinks to that one address. It is the only address any of their vendors ever sees, so when one of them leaks, what leaks is a forwarding label that points nowhere real. This is what an email alias is, and the setup guide takes about two minutes. The practice that makes it work, one alias per site, exists for exactly this scenario: companies you never dealt with holding your address anyway.
The other half is detection. If your bank holds only an alias, then a "Goldman Sachs tax update" arriving on any other address cannot have come from your bank. Which website leaked my email runs in reverse here: the alias does not just name the leaker after the fact, it exposes the imposter in the moment. There is nothing to inspect. An address you never handed that bank cannot belong to that bank. End of story.
Who else is in EY's queue?
EY has never published a total victim count, and the September letters give no per-firm numbers for Goldman Sachs or Man Group. The third-party platform vendor was never named. No one has said whether the stolen data has been misused since July; EY's no-evidence statement describes the findings at that stage, and the claim of responsibility is still unconfirmed. The thin secondary coverage adds nothing new.
What remains is the question the letters raise but do not answer: whose documents were in that queue that nobody has named yet. EY does tax work for institutions worldwide, the intruder downloaded documents connected to multiple clients, and the named firms are only the first set of letters. The original disclosure reporting is where the next set will surface.
Top comments (0)