Goldman Sachs and Man Group exposed in EY data breach

Clients of Goldman Sachs’ wealth management division and UK-listed hedge fund Man Group are among the victims of a major data breach at Big Four accounting firm EY, according to notifications sent out in recent weeks.

The disclosures widen the circle of victims of a hacking incident in March and April that the accounting firm first disclosed in July. It stemmed from a vulnerability in Checkmarx software, which had an impact on EY, several clients and many other organisations, EY said.

Several months after the attacks, EY has warned individuals who were clients of firms using EY’s tax services — including Goldman Sachs, Man Group and global real estate developer Tishman Speyer — that their personal and financial information had been compromised.

Cyber security has become a highly sensitive issue at professional services firms, which pitch themselves as expert advisers on the topic. Firms such as EY process client data on their systems and must take extensive precautions to prevent leaks, including negotiating bespoke terms with technology providers to segregate data on shared cloud infrastructure.

Letters sent to the affected clients at the end of September said that between March 28 and April 12 an “unauthorized third party” accessed the platform and downloaded documents pertaining to a number of EY clients.

The letters said personal information affected by the incident included “name, address, tax identifier, email address, financial information”. The letters were signed by Robb Canning, EY’s New York-based deputy ethics and compliance officer.

EY in July reported the incident to regulators in four US states: California, Texas, Massachusetts and Vermont. Notice to the state attorney-general is required when a single breach affects a number of residents over a given threshold.

The same month, cybercriminal group ShinyHunters claimed responsibility for the hack in a statement on its dark web leak site.

The largely anonymous group is considered by law enforcement to be a loose collective of young hackers responsible for large-scale data breaches at dozens of companies since 2020.

Last month, in what was arguably its highest-profile attack to date, ShinyHunters said it had hacked the FBI, stealing thousands of records relating to bureau personnel.

A week later, Dutch police announced the arrest of one of the alleged leaders of the group. The individual, whom the FBI did not name, and his co-conspirators had “allegedly breached more than 140 organizations and taken at least $70mn in extortion payments”, Brett Leatherman, FBI cyber division assistant director, said in a statement.

ShinyHunters could not be reached for comment.

Goldman told its wealth management clients last month that EY had hired an independent cyber security firm to confirm that systems involved in the incident were now secure.

“The Goldman Sachs Technology Risk team is independently reviewing their work, and we are requiring EY to demonstrate their remediation efforts are effective through objective evidence and third‑party validation,” the bank wrote in a letter to clients on September 24.

A Goldman Sachs spokesperson said: “We have been in regular contact with EY and are focused on working with them to support any of our clients impacted by their security incident. Goldman Sachs’ systems were not affected by this incident, and client assets at Goldman Sachs were not impacted and remain safe.”

A Man Group spokesperson said: “We were notified by EY of an incident involving third-party software. EY subsequently notified the individuals affected. This incident was independent of Man Group’s systems, which were not compromised.”

Recommended

In August, EY informed Tishman Speyer that information related to the global real estate developers’ investors might have been affected by the incident, according to regulatory filings. Tishman Speyer, whose internal systems were not impacted, declined to comment.

An EY spokesperson said the incident “did not impact broader EY enterprise systems and presents no threat to ongoing business”.

They added: “EY has conducted a comprehensive review of the affected data and the investigation is now in its final stages. We have been communicating the results of our analysis directly to clients as the review process concludes.”

The affected clients were told that EY was providing them with credit monitoring and identity protection from a third party.

Additional reporting by Ellesheva Kissin in London

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论