EY Data Breach Exposes Goldman Sachs and Man Group Clients’ Data, What the Lawsuit Means
Clients connected to Goldman Sachs’ wealth management business and Man Group are among the people whose personal and financial information was exposed in a 2026 data breach involving Ernst & Young LLP (EY), according to breach notifications filed with state regulators. Other EY clients, including Tishman Speyer, have also been reported among those affected.
The incident did not involve a reported compromise of Goldman Sachs’ or Man Group’s own internal systems. An unauthorized third party accessed a third-party information technology service-management platform used by EY employees supporting tax-related work. EY said the platform could contain documents attached to support tickets, including client tax information.
A proposed class action is already pending. Markishi Wyatt filed Wyatt v. Ernst & Young LLP, Case No. 1:26-cv-06108, in the U.S. District Court for the Southern District of New York on July 20, 2026. No class has been certified, and there is no settlement and no claim form at this time.
Quick Facts: EY Data Breach
| Detail | Information |
| Company involved | Ernst & Young LLP (EY) |
| Incident | Unauthorized access to a third-party IT service-management platform |
| Unauthorized access period | March 28 to April 12, 2026 |
| EY detected anomalous activity | April 23, 2026 |
| Clients publicly identified | Goldman Sachs wealth management clients, Man Group clients, and others |
| Data potentially involved | Personal and financial information in client-related documents; names, addresses, tax identification numbers, email addresses, and financial details have been reported |
| Lawsuit | Wyatt v. Ernst & Young LLP |
| Case number | 1:26-cv-06108 |
| Court | U.S. District Court for the Southern District of New York |
| Plaintiff / Defendant | Markishi Wyatt / Ernst & Young LLP |
| Class certified? | No |
| Settlement / claim form | None |
| Monitoring offered (Man Group notice) | 24 months of complimentary Experian IdentityWorks |
What Happened in the EY Data Breach?
EY uses a third-party IT service-management platform so its IT staff can support EY teams working on tax matters for clients. According to EY’s breach notice, support tickets submitted through the platform could contain documents with client tax information.
An unauthorized third party accessed the platform between March 28 and April 12, 2026 and downloaded documents relating to a number of EY clients. EY detected anomalous activity on April 23, began an incident-response investigation with an independent cybersecurity firm, worked to stop the access and secure the affected systems, and notified federal law enforcement. California’s Attorney General published EY’s breach notification, and additional notices were filed with other states. The total number of people affected has not been established in the public materials reviewed.
How Were Goldman Sachs Clients Affected?
Some people whose information EY handled through Goldman Sachs’ wealth management business were affected. The available information does not show that Goldman Sachs’ own systems were breached. Reporting on EY’s September notifications says Goldman Sachs told affected clients that its systems were not affected and that client assets were not impacted. The exposure concerns client information held by EY in connection with tax services.
That distinction does not remove the privacy concern. If your tax or financial information sat in the compromised EY environment, it could be exposed even though your bank or investment account itself was never breached.
How Were Man Group Clients Affected?
EY’s September 24, 2026 notice, filed with Massachusetts, states that EY was writing on behalf of Man Group and its applicable affiliates about a data-security incident. EY said it received personal information relating to recipients’ investment holdings while providing professional tax services, and that it had no indication the individual’s information was specifically targeted. Man Group’s own systems were not identified as the source of the compromise.
Related article: FBI ShinyHunters Data Breach, Contractor Removed After ShinyHunters Attack on PeopleSoft System

What Information Was Exposed?
It differs from person to person, so rely on the notice you received. EY’s notices confirm the compromised material could include personal information in documents tied to client tax work, and state filings and notices identify categories including personal identifying information and financial information. The public notices do not establish that every affected person had every category exposed.
What Does the EY Data Breach Lawsuit Allege?
The Wyatt complaint alleges that EY failed to adequately protect sensitive personal, financial, and tax information entrusted to it, and it seeks class treatment for others whose information was allegedly compromised. These are allegations only. The court has not certified a class and has not found EY liable. The lawsuit is against EY, and it does not establish that Goldman Sachs or Man Group caused the breach.
Is It a Certified Class Action?
No. It is a putative class action, meaning the plaintiff asks the court to let the case proceed on behalf of a larger group. No class-certification ruling exists in the materials reviewed.
Several related EY data-breach cases have been filed in the same court. The docket shows Wyatt was accepted as related to Hughes v. Ernst & Young LLP, No. 1:26-cv-06107, and other EY breach cases were identified as related to that proceeding. That does not mean the cases have been consolidated into one certified class action.
Current Status of the Lawsuit
The litigation is early. Wyatt was filed July 20, 2026. On September 3, it was reassigned to Judge Jeannette A. Vargas and accepted as related to Hughes. On September 17, it was referred to Magistrate Judge Valerie Figueredo for general pretrial matters, including discovery and other non-dispositive proceedings. There is no court-approved settlement fund.
Is There a Settlement or Claim Form?
No. There is no verified EY 2026 data-breach settlement and no court-authorized claim form. A lawsuit being filed does not mean affected people are automatically entitled to money. If the case later settles or reaches judgment, the court could approve a notice and claims process, but that has not happened.
For comparison, see how a real data-breach settlement works in ModMed Data Breach Settlement, $2.99M Fund, Claim by November 2, 2026, which has a court-authorized process and claim deadline. The EY litigation does not.
What Affected People Should Do
- Keep your breach letter. It explains why you were contacted and may contain an enrollment code.
- Enroll in the identity-monitoring service offered in your notice. The Man Group notice offers 24 months of Experian IdentityWorks. Don’t assume the same service applies to everyone.
- Watch financial and investment accounts for transactions or changes you don’t recognize.
- Be cautious with targeted messages. Exposed tax or investment details can make phishing and impersonation attempts convincing.
- Consider a fraud alert or credit freeze with the major credit bureaus. These are separate from any monitoring EY offers.
- Do not pay anyone to file an EY settlement claim. No court-authorized process exists.
If you believe you suffered a specific loss, consider speaking with a qualified attorney about your circumstances.
What Happens Next
The immediate issues are procedural. The court must decide how the related EY cases proceed and whether they will be coordinated. EY will have the chance to respond to the allegations, and later stages could include motions challenging the claims, discovery on the compromised platform and EY’s security practices, and potentially a motion for class certification. None of this is a finding that EY caused compensable harm unless a court so rules or the parties reach an approved settlement.
Key Dates
| Date | Event |
| March 28, 2026 | EY says unauthorized access to the platform began |
| April 12, 2026 | End of the access period identified by EY |
| April 23, 2026 | EY confirms anomalous activity |
| July 15, 2026 | California Attorney General publishes EY’s breach notification |
| July 19-20, 2026 | Initial EY breach lawsuits filed in the Southern District of New York |
| September 3, 2026 | Wyatt reassigned to Judge Vargas and accepted as related to Hughes |
| September 17, 2026 | Case referred to Magistrate Judge Figueredo for pretrial matters |
| September 24, 2026 | EY notice to affected Man Group clients dated |
| October 2026 | Public reporting identifies Goldman Sachs and Man Group clients among those affected |
| Current | Litigation pending; no certified class or settlement claim process |
Frequently Asked Questions
Did Goldman Sachs suffer a direct data breach?
Not according to the information verified here. The affected information was held by EY, and Goldman Sachs’ own systems were reported as unaffected.
Were Man Group’s systems hacked?
EY’s notice identifies EY’s platform as the location of the incident, not Man Group’s systems.
What personal information was exposed?
It varies by person. EY’s notices indicate documents containing client tax and personal information were downloaded, and the Man Group notice concerns personal information relating to investment holdings.
Is there an EY data breach class action?
Yes. Wyatt v. Ernst & Young LLP, No. 1:26-cv-06108 (S.D.N.Y.), is a proposed class action. It has not been certified.
Can I file an EY settlement claim?
No. There is no verified settlement or claim form.
Are Goldman Sachs or Man Group clients eligible for money from the lawsuit?
Not at this stage. No settlement or court-authorized compensation process exists. Follow your individual notice and monitor the litigation.
What should I do if I received an EY breach letter?
Read it carefully, enroll in any offered monitoring, keep the notice, watch your accounts, and stay alert for phishing or fraud.
Sources
- California Attorney General, Ernst & Young LLP breach notification: https://oag.ca.gov/ecrime/databreach/reports/sb24-626542
- Massachusetts, EY notice concerning Man Group clients (Sept. 24, 2026): https://www.mass.gov/doc/2026-1622-man-group/download
- Massachusetts, EY notice letter (Tishman Speyer filing): https://www.mass.gov/doc/2026-1568-tishman-speyer/download
- Wyatt v. Ernst & Young LLP, No. 1:26-cv-06108 (S.D.N.Y.), federal docket: https://dockets.justia.com/docket/new-york/nysdce/1%3A2026cv06108/668651
- Hughes v. Ernst & Young LLP, No. 1:26-cv-06107 (S.D.N.Y.), related federal docket: https://dockets.justia.com/docket/new-york/nysdce/1%3A2026cv06107/668650
- Financial Times, “Goldman Sachs and Man Group exposed in EY data breach”: https://www.ft.com/content/2ad1ff25-f08e-4e78-83c9-90e7ea3844ee
Researched and written by Israr Ahmad, Legal Content Researcher.
This article is for informational purposes only and is not legal advice. AllAboutLawyer.com is a U.S. consumer legal information website, not a law firm, and does not provide legal representation. Lawsuit allegations are not findings of fact or liability. Case status, breach scope, and available protections can change as additional court filings and regulatory notices become available.
About the Author
Israr Ahmad is a legal content researcher with 4+ years of experience covering class action settlements and consumer rights cases. He has researched and published coverage of 2,500+ settlements using verified court records, settlement administrator filings, and government sources. Learn more about Israr.
