The disclosures broaden the known impact of a cyber incident first reported to US regulators in July. Affected information included names, addresses, tax identifiers, email addresses and financial details connected with investment holdings, according to notices sent to individuals whose information was held by EY while providing tax services.
Goldman Sachs and Man Group said their own systems were not compromised. Goldman Sachs said client assets held at the bank were unaffected and remained safe, while Man Group said the incident was independent of its systems.
EY said the intrusion involved a third-party information technology service-management platform used by its technology personnel to support teams carrying out tax-related work for clients. Support tickets submitted through the platform could contain documents with client tax information.
The accounting firm confirmed anomalous activity on the platform on April 23 and activated its incident-response procedures. Its investigation, assisted by an independent cybersecurity company, found that an unauthorised third party had accessed the platform between March 28 and April 12 and downloaded documents relating to a number of EY clients.
Notifications sent at the end of September identified clients associated with Goldman Sachs’ wealth management division, London-listed Man Group and property developer Tishman Speyer among those affected. The latest notices therefore provide a clearer picture of which organisations had customer or investor information caught in the compromise, although EY has not publicly disclosed a total number of affected people or clients.
EY said it notified federal law enforcement and took steps to contain the incident. The firm has also offered affected individuals credit monitoring and identity-protection services. It said an independent cybersecurity specialist was engaged to help investigate the intrusion and validate the security of the affected environment.
The breach had already entered the public record through US state notification systems. California’s attorney-general database lists an Ernst & Young LLP breach beginning on March 28, with the company submitting a notification in July. Massachusetts has also published EY-related notices describing the compromise and the information potentially involved.
The California filing is significant because state law requires organisations to provide the attorney general with a sample notice when a breach notification is sent to more than 500 California residents. The filing itself does not establish the overall number of people affected across EY’s clients or jurisdictions.
The incident has drawn particular attention because the compromised platform was part of the service chain supporting tax work rather than the core networks of Goldman Sachs or Man Group. Financial institutions routinely depend on professional-services firms and technology suppliers to process sensitive information, creating additional locations where customer data must be protected.
EY has linked the broader incident to a vulnerability affecting Checkmarx software and said the issue affected EY, some clients and other organisations. Public disclosures do not establish that the Goldman Sachs and Man Group networks were penetrated through that vulnerability. The financial firms have explicitly said their systems were unaffected.
Cybercriminal group ShinyHunters has claimed responsibility for the attack, but that assertion has not been independently established by law enforcement in the public notices. EY’s regulatory notifications describe the intruder as an unauthorised third party rather than naming a group.
The exposed combination of identity, tax and investment information can carry risks beyond ordinary account credentials because some identifiers are difficult to replace. EY’s notices advise affected individuals to monitor accounts and credit reports for suspicious activity and to remain alert to identity theft or fraud.
EY provides tax services to financial institutions globally, requiring it to process client information for tax preparation and work. That role placed investment records within the affected support workflow.
Follow Arabian Post
Select Arabian Post as your preferred source on Google and MSN News for trusted business news and Arab politics and updates.