
Sensitive corporate data can be stolen through routine workplace software without triggering traditional cyber defences, according to a warning from Darktrace. The cybersecurity firm issued the caution following a breach at the Big Four accounting giant EY, which exposed information linked to major financial institutions including Goldman Sachs and Man Group. The incident underscores a growing vulnerability in how businesses handle data once it leaves their own secure networks and enters third-party platforms.
Nathaniel Jones, senior vice president of global threat intelligence at Darktrace, explained that attackers are increasingly capable of hiding their activities within legitimate software operations. He noted that document theft often mimics normal business activity, making it difficult for standard security controls to detect. Traditional systems are effective at identifying malware or known malicious infrastructure, but they often fail to flag an attacker using a legitimate account to browse and download files. This creates a significant blind spot, particularly as companies rely more heavily on external accountants and software providers for day-to-day operations.
In the specific EY incident, the networks of both Goldman Sachs and Man Group remained secure. The breach occurred because EY stored sensitive tax documents as attachments to internal IT support tickets on a platform it utilised. An unauthorised third party accessed this platform between 28 March and 12 April, downloading documents linked to multiple clients. The stolen information included personal details such as names, addresses, and email addresses, as well as tax identification numbers and financial data. EY did not detect the unusual activity until 23 April, which was 11 days after the last reported unauthorised access. The firm stated that the breach did not impact its broader enterprise systems or present a threat to ongoing business, and that the investigation is now in its final stages.
Jones highlighted that the core issue is the shift of operations onto third-party and cloud software. While organisations have spent years securing access to applications, they are now struggling to secure the data inside them. Once sensitive information is uploaded to a supplier’s platform, it can move beyond the controls and monitoring that would normally protect it within a company. This makes operational platforms attractive targets for hackers, as they can contain high-value information without being monitored as rigorously as core production environments. Jones emphasised the need for visibility into where data goes, who can access it, and how long it is retained.
Goldman Sachs confirmed that its own systems were unaffected and that client assets remained safe. The bank stated it has been in regular contact with EY to support impacted clients. Additionally, Goldman’s technology risk team has requested objective evidence and third-party checks to verify that EY’s remediation measures have been effective. Man Group similarly stated that the incident was independent of its systems, which were not compromised. The episode serves as a reminder that securing the perimeter is no longer sufficient when data is distributed across various external platforms.
The following content has been published by Stockmark.IT. All information utilised in the creation of this communication has been gathered from publicly available sources that we consider reliable. Nevertheless, we cannot guarantee the accuracy or completeness of this communication.
This communication is intended solely for informational purposes and should not be construed as an offer, recommendation, solicitation, inducement, or invitation by or on behalf of the Company or any affiliates to engage in any investment activities. The opinions and views expressed by the authors are their own and do not necessarily reflect those of the Company, its affiliates, or any other third party.
The services and products mentioned in this communication may not be suitable for all recipients, by continuing to read this website and its content you agree to the terms of this disclaimer.