Sensitive corporate data, including information linked to Goldman Sachs and Man Group, was exposed in a breach at EY. The incident involved an unauthorised third party accessing an EY platform and downloading documents attached to internal IT support tickets.
The breach occurred between 28 March and 12 April, with EY not detecting unusual activity until 23 April. Information exposed included names, addresses, email addresses, tax identification numbers, and financial details of multiple EY clients.
Darktrace, a cybersecurity firm, warned that such data theft can occur through everyday workplace software without triggering traditional cyber defences. Nathaniel Jones, senior vice president of global threat intelligence at Darktrace, stated that attackers are increasingly able to hide among legitimate activity, as document theft often resembles normal business operations.
Both Goldman Sachs and Man Group confirmed their own systems were not compromised. Goldman Sachs has requested "objective evidence and third-party checks" to confirm EY's remediation efforts have been effective.