Skip to content

Leadership1 publisherNot yet confirmed elsewhere3 min readPublished

EY's IT support platform exposed tax files linked to Goldman Sachs and Man Group

EY spotted unusual activity on a support-ticket platform holding client tax files on 23 April, 11 days after the last reported unauthorised access. Goldman Sachs and Man Group say their own networks held. The weak point lay in the adviser's tools.

The Board Room · Leadership desk

How we use AISend a correction

Photograph accompanying EY's IT support platform exposed tax files linked to Goldman Sachs and Man Group
Photo: cityam.com

What happened

  • EY kept sensitive client tax documents as attachments to internal IT support tickets on a platform the firm used.
  • An unauthorised third party accessed that platform between 28 March and 12 April and downloaded documents linked to multiple EY clients.
  • The exposed information included names, addresses, email addresses, tax identification numbers and financial details.
  • Darktrace warned that corporate data can be stolen through everyday workplace software without setting off traditional cyber defences.

Compiled by The Board RoomSomething wrong?How this is made

Why it matters

  • exposure A client with a secure network still carries risk in every internal tool an adviser uses to handle its files, including help desks that hold attachments.
  • constraint Controls built to catch malware and known bad infrastructure are weaker against downloads by an account that looks legitimate, so an adviser's standard security assurances cover less of this risk.
  • decision Clients reviewing their accountants and advisers must choose whether to extend checks to ticketing and file-handling tools, at the price of more work on every engagement.

Counted from the start of the access window, EY took 26 days to notice anything unusual [11]. A business can secure its own network and still lose sight of documents once someone uploads them elsewhere, according to the City AM report [19].

Nathaniel Jones, senior vice president of global threat intelligence at Darktrace [20], explained why theft of this kind goes unseen. "Traditional controls are good at detecting malware, exploits, or known malicious infrastructure, but they are often less effective when an attacker is using a legitimate account to browse and download files," he said [13]. The report lists the warning signs as ordinary ones: an account downloading more documents than usual, opening files that belong to different clients, or logging in from an unusual location [14]. It does not say how the third party got into EY's platform, so Jones's comments describe a pattern and do not diagnose this breach.

Jones said the larger weakness is growing as companies shift more of their routine operations onto cloud and third-party software [21]. "Attackers know this, and they are increasingly targeting operational platforms because those systems can contain high-value information without always being monitored like core production environments," he said [18].

Goldman Sachs stressed that its own systems were unaffected and client assets remained safe [10]. A spokesperson said: "As with other clients we understand were affected, we have been in regular contact with EY and are focused on working with them to support any of our clients impacted by their security incident" [4]. The records belonged to clients even while they sat on an adviser's help desk. Jones drew the same line. "Organisations have spent years securing access to applications. The challenge is securing access to the data inside them," he said [15].

The trade-off for a client is the friction of examining an adviser's internal tools against the risk of not knowing where its files travel. Jones set out the questions: "If tax documents or corporate data can be attached to tickets, organisations need visibility into where that data goes, who can access it, how long it is retained, and whether it is being downloaded at scale" [16]. Answering them means an accounting firm opening its help desk and file-handling systems to every client that asks. Each request adds work to an engagement. In my view that cost is easiest to justify with advisers that hold tax and financial records, and hardest to justify for suppliers that never touch a client document.

Goldman's technology risk team has asked for "objective evidence and third-party checks" that EY's remediation has worked [5]. "Organisations want proof that remediation has worked, not simply evidence that the right processes exist on paper," Jones said [17]. Other affected clients now have to decide whether to make the same demand. An adviser that accepts independent checks for one bank will find them harder to refuse the next client, and someone pays for the verification, either in fees or out of the adviser's margin. We do not know yet which. EY declined to comment [7].

What to watch

  • Whether EY discloses how the third party got into the platform and how many clients' documents were downloaded.
  • Whether EY gives Goldman Sachs the independent verification its technology risk team requested, and whether other affected clients ask for the same.
  • Whether further EY clients beyond Goldman Sachs and Man Group confirm their data was among the downloaded documents.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories