Clients of Goldman Sachs’ wealth management division and the UK-listed hedge fund Man Group have been identified as victims of a significant data breach at the Big Four accounting firm EY, according to notifications sent to affected individuals in recent weeks. The breach, which EY initially disclosed in July, occurred between March 28 and April 12 and exploited a vulnerability in Checkmarx software, impacting EY, several of its clients, and other organizations.

The breach involved unauthorized access to sensitive personal and financial information of clients utilizing EY’s tax services, including those linked to Goldman Sachs, Man Group, and real estate developer Tishman Speyer. According to letters sent to those affected, the compromised data encompassed names, addresses, tax identifiers, email addresses, and financial details. The letters were signed by Robb Canning, EY’s deputy ethics and compliance officer based in New York.

EY reported the incident to regulatory authorities in multiple U.S. states—California, Texas, Massachusetts, and Vermont—in July, in compliance with laws requiring notification when a breach affects a certain number of residents. That same month, the cybercriminal group known as ShinyHunters claimed responsibility for the attack.

In response, EY said the breach did not affect its broader enterprise systems and posed no ongoing threat to its business operations. The firm has engaged an independent cybersecurity company to assess and confirm that the affected systems are now secure. Goldman Sachs and Man Group have both stated that their internal systems were not compromised, while Tishman Speyer also confirmed no impact on its own systems.

The incident has underscored growing concerns about cybersecurity risks within professional services firms, which frequently manage vast amounts of sensitive client data and promote themselves as cybersecurity experts. These firms typically implement strict safeguards, including tailored agreements with technology vendors to ensure proper data segregation on shared cloud platforms.

EY has indicated that its comprehensive review of the compromised data is nearing completion and that clients will be informed individually as the process concludes. The firm has made efforts to reassure clients and regulators as the investigation continues.