Goldman Says Client Assets Are Safe. Its Risk Team Is Asking EY to Prove It

An intruder sat inside an EY tax-support platform from March 28 to April 12, 2026, downloading client documents; letters naming Goldman's wealth clients landed only in late September. Goldman's public "assets remain safe" now runs beside a September 24 letter in which its own risk team demands proof that EY's fixes work.

In this storyGS
Vincent JiangVincent Jiang · 4 min read
Share
David Solomon, chairman and chief executive of Goldman Sachs, smiling beside then-US defense secretary Mark Esper
1 / 6Slide 1 of 6
Goldman Sachs chairman and chief executive David Solomon, left, with then-defense secretary Mark Esper in New York, November 2019. Solomon's firm says client assets remain safe while its technology risk team demands proof from EY.

Wealth clients learned about the helpdesk in September

Letters that reached clients of Goldman Sachs' wealth business in late September carried an awkward confession: an unauthorized party had downloaded their tax documents from a support platform at EY, their tax accountant 1. Individuals linked to Man Group (LSE: EMG) got the same news 1. Goldman's presence in the stolen set surfaced publicly on October 6 2.

The systems were safe; the files were not

Goldman's public line is that its systems were untouched and client assets "remain safe" 2, and that it is working with EY "to support any of our clients impacted by their security incident" 3. Man Group called the incident "independent of Man Group's systems, which were not compromised" 4. Wealth clients bought discretion, and discretion left the building as a helpdesk attachment: names, addresses, tax identification numbers and financial details, riding on internal IT support tickets 14.

In private, Goldman stopped taking EY's word

Goldman's September 24 letter to clients is where the two lines meet 1. It said EY had engaged an independent cybersecurity firm to verify the affected systems were secure, and that Goldman's own technology risk team was demanding "objective evidence and third-party checks" that the fixes worked 14. EY had spotted the unusual activity on April 23, 11 days after the intruder's window closed 1. The entry point was reportedly a flaw in Checkmarx software; no CVE is identified 1.

DateWhat happened
March 28, 2026Intruder enters EY's tax-support helpdesk platform
April 12, 2026The intruder's window closes
April 23, 2026EY spots the unusual activity, 11 days later
July 2026EY's notice reports no evidence of misuse; filings land in four states
September 24, 2026Goldman's letter demands objective evidence that EY's fixes work
Late September 2026Client letters reach Goldman wealth and Man Group individuals
October 6, 2026Goldman's presence in the stolen set surfaces publicly
October 31, 2026Enrollment in EY's 24 months of Experian monitoring closes
The arc of the EY breach, from first entry to Goldman's demand for proof, as reported in client letters, state filings and press accounts.

The only hard count is a floor

Filings with regulators in California, Texas, Massachusetts and Vermont confirm a floor of 1,366 affected residents, the first verifiable measure of scale 5. Massachusetts lists at least 19 residents tied to Man Group, notified by EY on the fund's behalf 6. EY is offering 24 months of Experian identity monitoring, and enrollment closes October 31 5.

EY's July notice found no evidence of misuse, a stage finding rather than a close 1. The record is otherwise blunt: this is EY's third significant data security incident in less than three years, and all three trace back to a third-party vendor or platform 5. The one before this, MOVEit, exposed 30,210 Bank of America customers and settled this year for $2.5 million 5.

EY carries the bill; the wealth book carries the risk

The damage splits along a clean line: EY carries the direct bill (credit monitoring, filings in four states, the MOVEit settlement behind it), while Goldman's wealth franchise carries the attrition and regulator follow-on that no public statement can call back 15. EY says the incident never reached its broader enterprise systems and that its review is nearing completion 1. Asked this week, it declined to comment 4.

Proof, not processes on paper

The demand in Goldman's letter matches what security vendors now say out loud. Darktrace's Nathaniel Jones, senior vice president of global threat intelligence, puts the 11-day detection gap down to method: attackers "using a legitimate account to browse and download files" 4. His standard for closing it is Goldman's: "organizations want proof that remediation has worked, not simply evidence that the right processes exist on paper" 4.

The count nobody has printed is the number that matters

No report establishes how many Goldman-linked individuals sit in the stolen set 1. A class-action investigation into Man Group claims is already open 6. Until that count and EY's review land, the tail on this incident stays unpriced, and each new state filing marks it again: EY has filed in only four so far 15.

Deepdive

AI-generated from this story and its cited sources. Not investment advice.

Reader comments

0 comments

    Sign up

    Get your curated digest

    After email confirmation, you will receive a daily digest of the most relevant news that matter to your portfolio