Goldman Says Client Assets Are Safe. Its Risk Team Is Asking EY to Prove It
An intruder sat inside an EY tax-support platform from March 28 to April 12, 2026, downloading client documents; letters naming Goldman's wealth clients landed only in late September. Goldman's public "assets remain safe" now runs beside a September 24 letter in which its own risk team demands proof that EY's fixes work.
Vincent Jiang · 4 min read
Wealth clients learned about the helpdesk in September
Letters that reached clients of Goldman Sachs' wealth business in late September carried an awkward confession: an unauthorized party had downloaded their tax documents from a support platform at EY, their tax accountant 1. Individuals linked to Man Group (LSE: EMG) got the same news 1. Goldman's presence in the stolen set surfaced publicly on October 6 2.
The systems were safe; the files were not
Goldman's public line is that its systems were untouched and client assets "remain safe" 2, and that it is working with EY "to support any of our clients impacted by their security incident" 3. Man Group called the incident "independent of Man Group's systems, which were not compromised" 4. Wealth clients bought discretion, and discretion left the building as a helpdesk attachment: names, addresses, tax identification numbers and financial details, riding on internal IT support tickets 14.
In private, Goldman stopped taking EY's word
Goldman's September 24 letter to clients is where the two lines meet 1. It said EY had engaged an independent cybersecurity firm to verify the affected systems were secure, and that Goldman's own technology risk team was demanding "objective evidence and third-party checks" that the fixes worked 14. EY had spotted the unusual activity on April 23, 11 days after the intruder's window closed 1. The entry point was reportedly a flaw in Checkmarx software; no CVE is identified 1.
| Date | What happened |
|---|---|
| March 28, 2026 | Intruder enters EY's tax-support helpdesk platform |
| April 12, 2026 | The intruder's window closes |
| April 23, 2026 | EY spots the unusual activity, 11 days later |
| July 2026 | EY's notice reports no evidence of misuse; filings land in four states |
| September 24, 2026 | Goldman's letter demands objective evidence that EY's fixes work |
| Late September 2026 | Client letters reach Goldman wealth and Man Group individuals |
| October 6, 2026 | Goldman's presence in the stolen set surfaces publicly |
| October 31, 2026 | Enrollment in EY's 24 months of Experian monitoring closes |
The only hard count is a floor
Filings with regulators in California, Texas, Massachusetts and Vermont confirm a floor of 1,366 affected residents, the first verifiable measure of scale 5. Massachusetts lists at least 19 residents tied to Man Group, notified by EY on the fund's behalf 6. EY is offering 24 months of Experian identity monitoring, and enrollment closes October 31 5.
EY's July notice found no evidence of misuse, a stage finding rather than a close 1. The record is otherwise blunt: this is EY's third significant data security incident in less than three years, and all three trace back to a third-party vendor or platform 5. The one before this, MOVEit, exposed 30,210 Bank of America customers and settled this year for $2.5 million 5.
EY carries the bill; the wealth book carries the risk
The damage splits along a clean line: EY carries the direct bill (credit monitoring, filings in four states, the MOVEit settlement behind it), while Goldman's wealth franchise carries the attrition and regulator follow-on that no public statement can call back 15. EY says the incident never reached its broader enterprise systems and that its review is nearing completion 1. Asked this week, it declined to comment 4.
Proof, not processes on paper
The demand in Goldman's letter matches what security vendors now say out loud. Darktrace's Nathaniel Jones, senior vice president of global threat intelligence, puts the 11-day detection gap down to method: attackers "using a legitimate account to browse and download files" 4. His standard for closing it is Goldman's: "organizations want proof that remediation has worked, not simply evidence that the right processes exist on paper" 4.
The count nobody has printed is the number that matters
No report establishes how many Goldman-linked individuals sit in the stolen set 1. A class-action investigation into Man Group claims is already open 6. Until that count and EY's review land, the tail on this incident stays unpriced, and each new state filing marks it again: EY has filed in only four so far 15.
Deepdive
AI-generated from this story and its cited sources. Not investment advice.



