Data on Goldman Sachs clients was affected by a breach of accountancy firm EY earlier this year, according to a person familiar with the matter.
A Goldman Sachs spokesperson said via email that its internal systems were not affected and that client assets “remain safe”.
“We have been in regular contact with EY and are focused on working with them to support any of our clients impacted by their security incident,” the spokesperson stated.
Sensitive data
The earlier reported that the data breach in March and April, which was claimed by the ShinyHunters hacking group, affected data on clients of Goldman’s wealth management division and of UK-listed hedge fund Man Group.
The hack involved a vulnerability in Checkmarx software, which also affected several clients and many other organisations, EY said at the time.
At the end of September, EY sent notifications about the breach to individuals who were clients of EY’s tax services, including Goldman Sachs, Man Group and real estate developer Tishman Speyer, according to the report.
Between 28 March and 12 April, an “unauthorised third party” accessed systems and downloaded data including names, addresses, tax identifiers, email addresses, and financial information, the letters reportedly said.
ShinyHunters more recently claimed to have stolen detailed employment and health data on virtually all employees of the US Federal Bureau of Investigation, leading to coordinated international efforts to track down members of the group.