Decoding the world of cybersecurity

EY breach exposes financial data held for major clients

Personal and financial information held by EY for clients including Man Group was exposed after attackers compromised technology used within the professional services firm’s tax operations.

EY breach exposes financial data held for major clients
Summary
  • EY has notified individuals whose information was affected through its tax services work.
  • A Massachusetts filing confirms exposure involving information held for Man Group.
  • Wider reporting links the incident to vulnerable Checkmarx technology and additional clients.

EY has begun notifying individuals whose personal and financial information was exposed in a security incident affecting technology used within its tax services operation, extending the consequences of the compromise into data belonging to major clients.

A breach notification filed in Massachusetts on behalf of Man Group confirms that EY held personal information connected with investment holdings while providing professional tax services to the asset manager and its affiliates. Affected individuals were told that their information had been involved in a security incident within EY’s environment.

Goldman Sachs Wealth Management and property group Tishman Speyer were also among organisations affected, according to reporting by the Financial Times, which linked the intrusion to vulnerable Checkmarx technology used by EY. The precise information exposed differs between clients and individuals, so the confirmed impact should not be treated as a single uniform dataset.

The activity took place between late March and mid-April, while subsequent notifications and regulatory filings have begun to establish which organisations and people were affected. That sequence means the operational compromise and the eventual disclosure to individuals sit several months apart.

For Man Group, the filing demonstrates how information supplied for an ordinary professional services engagement moved beyond the client’s own systems. EY received the data because it was carrying out tax work, placing information belonging to investors inside another organisation’s technology environment.

Professional services firms occupy an unusually concentrated position in that respect. Banks, asset managers and other regulated companies routinely provide auditors, accountants, law firms and specialist advisers with sensitive customer, employee and transaction data, allowing one supplier environment to contain information originating from several otherwise separate organisations.

A further dependency emerges if vulnerable Checkmarx software provided the initial route into the affected EY environment. The client then depends on EY’s security controls, while EY in turn depends on technology supplied and maintained by another company. Remediation may involve each organisation even though the original client did not operate the vulnerable software itself.

Those relationships can complicate incident response because the organisation holding the data, the organisation to which the data relates and the supplier responsible for an affected component may have different contractual, regulatory and notification obligations. Establishing the affected records becomes a prerequisite for determining which regulators and individuals need to be informed.

The same structure also limits what can safely be inferred from criminal claims. Attackers associated publicly with the incident have made broader assertions about information taken from EY environments, but those claims remain separate from data exposure established through regulatory notices and attributable statements from affected organisations.

Client organisations can therefore face material consequences without suffering a direct intrusion into their own networks. Sensitive information may leave the organisation through legitimate business processes, remain inside a supplier for operational reasons and later become exposed because another component of that supplier’s environment is compromised.

As professional services firms increasingly operate shared technology platforms across tax, audit and advisory functions, those environments become part of the security perimeter of the clients whose information they process. The concentration is commercial as well as technical, because one incident can trigger notification, investigation and contractual work across several organisations at once.

The Massachusetts filing confirms the downstream impact for Man Group, while the full number of organisations and individuals affected by the wider EY incident has not been publicly established.

×