Clients of Goldman Sachs’ wealth management division and UK-listed hedge fund Man Group are among the victims (paywall) of a major data breach at Big Four accounting firm EY, according to notifications sent out in recent weeks.
In other words, this is bad.
Commenting on this is Paul Bischoff, Consumer Privacy Advocate at Comparitech:
“This breach underlines how modern businesses rely on multiple layers of third-party software over which they have minimal oversight. Goldman Sachs didn’t get hacked. A vendor to a vendor to Goldman Sachs got hacked. Goldman Sachs entrusts client data to both of those vendors but has little to no oversight of either’s security. But clients entrusted Goldman Sachs with their data, not the vendors. Businesses are responsible for the security failures of vendors that they entrust with private data.”
Third party hacks are a thing. So if you assume that you’re only secure as the people you work with, you need to audit those people to ensure that you are secure.
Related
This entry was posted on October 7, 2026 at 1:32 pm and is filed under Commentary with tags Comparitech. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
Goldman Sachs and Man Group exposed in EY data breach
Clients of Goldman Sachs’ wealth management division and UK-listed hedge fund Man Group are among the victims (paywall) of a major data breach at Big Four accounting firm EY, according to notifications sent out in recent weeks.
In other words, this is bad.
Commenting on this is Paul Bischoff, Consumer Privacy Advocate at Comparitech:
“This breach underlines how modern businesses rely on multiple layers of third-party software over which they have minimal oversight. Goldman Sachs didn’t get hacked. A vendor to a vendor to Goldman Sachs got hacked. Goldman Sachs entrusts client data to both of those vendors but has little to no oversight of either’s security. But clients entrusted Goldman Sachs with their data, not the vendors. Businesses are responsible for the security failures of vendors that they entrust with private data.”
Third party hacks are a thing. So if you assume that you’re only secure as the people you work with, you need to audit those people to ensure that you are secure.
Share this:
Like this:
Related
This entry was posted on October 7, 2026 at 1:32 pm and is filed under Commentary with tags Comparitech. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.