A cyber breach at EY exposed information connected to clients of Goldman Sachs’ wealth business, Man Group and property group Tishman Speyer, the Financial Times reported. The incident involved a third-party IT service-management platform and a vulnerability in Checkmarx software, rather than a compromise of the financial firms’ own systems.
The affected data included names, addresses, tax identifiers, email addresses and financial information. According to the report, unauthorised access occurred between 28 March and 12 April. EY said its broader enterprise systems were not affected and that its investigation was in its final stages. Goldman Sachs and Man Group said their systems were not compromised and client assets remained safe.
The episode is a useful reminder that “our systems were not breached” is not the same as “our customers’ data was not exposed”. Professional-services firms, software providers and outsourced operations can hold information that is just as sensitive as data inside a bank or asset manager.
For regulated organisations, supplier reviews should therefore cover sub-processors, vulnerability disclosure, incident-notification speed, evidence of remediation and the exact data each provider can access. Contractual assurance alone is weak if it cannot be matched to a live dependency map and tested response plan.
