Were you recently affected by a data breach?

Tishman Speyer Data Breach

Tishman Speyer notified investors that their personal information was exposed in a data breach at Ernst & Young, its tax services provider, after an unauthorized party accessed an IT platform between March 28 and April 12, 2026. Free credit monitoring is offered.

Tishman Speyer
Date of Breach: Between March 28, 2026, and April 12, 2026 (at vendor Ernst & Young LLP)
CAU logo

Who was affected:

Clients of Tishman Speyer

Impacted Data:

Personal identifiable information related to investment holdings (specific categories vary by individual; bank account numbers, income, and net worth excluded)

Tishman Speyer, a global real estate development and investment firm, recently notified certain investors that their personal information was exposed as part of a data security incident at Ernst & Young LLP (EY), the accounting and professional services firm that provides Tishman Speyer with tax preparation services.

Companies that share sensitive personal and financial information with outside professional service providers have a responsibility to ensure that information remains protected, even when the exposure originates with a vendor rather than the company’s own systems.

Tishman Speyer’s Data Breach Investigation

According to a notification letter, Ernst & Young LLP provides professional tax services to a wide range of financial institutions and investment firms globally, including Tishman Speyer, and received certain personal information relating to Tishman Speyer investors’ holdings in the course of that work. EY states that its own investigation determined that an unauthorized third party accessed a third-party information technology service management platform used by EY’s IT personnel to support tax-related client work, and downloaded documents pertaining to a number of EY clients between March 28, 2026, and April 12, 2026.

EY says it confirmed the anomalous activity on April 23, 2026, and immediately activated its incident response procedures, engaging an independent cybersecurity firm and notifying federal law enforcement. On August 6, 2026, EY notified Tishman Speyer that information related to Tishman Speyer investors may have been affected by the incident. EY states it then worked to identify the specific individuals impacted, a process it describes as time-intensive given the nature of the dataset involved, and completed that process on August 25, 2026, at which point Tishman Speyer began notifying affected investors. The notification letter is explicit that Tishman Speyer’s own internal systems were not impacted by the incident; the exposure occurred entirely within EY’s third-party platform.

This incident illustrates a risk that extends well beyond any single company’s own network security: a firm can maintain excellent internal cybersecurity and still see its customers’ or investors’ information exposed because a vendor or service provider it relies on was compromised instead. Tax preparation and accounting firms like EY routinely handle highly sensitive financial documents on behalf of their clients’ own customers and investors, meaning a single vendor-side breach can ripple outward to affect people who have no direct relationship with the vendor and may not have even known their information was in the vendor’s hands.

Public reporting on this incident has noted that EY’s broader breach affected numerous clients across multiple industries, with confirmed notifications filed with state attorneys general in California, Massachusetts, Texas, and Vermont, among others, and a combined total of well over a thousand residents confirmed affected in public state filings alone. The full scope of individuals affected across all of EY’s impacted clients, including Tishman Speyer investors, has not been publicly disclosed by EY, as the company has not released a single nationwide total.

Investors and individuals whose financial or tax-related information was exposed in an incident like this face particular risk because these documents can include Social Security numbers, bank account information, and other financial identifiers that are highly valuable for identity theft, tax-refund fraud, and fraudulent account openings. The multi-month gap between the initial intrusion in the spring of 2026 and individual notifications going out in the late summer reflects the scale and complexity of determining exactly which individuals across which of EY’s many clients were affected, a process that inherently takes longer as the number of impacted organizations grows.

Tishman Speyer’s prompt notification once EY confirmed which investors were affected, and its clear statement that its own systems were not compromised, reflects appropriate handling of a vendor-side incident. Even so, affected investors deserve the same protections and support as they would in a breach originating directly with the company holding their information, which is why EY is offering credit and identity monitoring services regardless of where the exposure technically occurred.

Vendor and supply-chain breaches like this one have become an increasingly common pathway for large-scale data exposure, precisely because a single compromised service provider can sit in the data-handling chain for dozens or hundreds of separate client organizations at once. Rather than attacking each company’s investors directly, threat actors increasingly target the professional services firms, IT platforms, and support vendors that many companies rely on in common, since a single successful intrusion there can yield sensitive records belonging to a much wider set of individuals across many unrelated companies.

For Tishman Speyer investors specifically, the practical risk profile is similar to what it would be in a direct breach: the same categories of financial and personal information can end up exposed regardless of whether the point of failure was Tishman Speyer’s own systems or a vendor’s platform three steps removed. Affected investors should not assume that a vendor-side incident is inherently lower-risk than a direct breach simply because the notifying company’s own systems were not compromised.

When Did This Breach Occur?

According to the notification letter, the unauthorized access to EY’s third-party IT platform occurred between March 28, 2026, and April 12, 2026. EY detected the anomalous activity on April 23, 2026, and notified Tishman Speyer that its investors’ information may have been affected on August 6, 2026. EY completed the process of identifying the specific affected individuals and notified Tishman Speyer on August 25, 2026, after which Tishman Speyer began sending notification letters to affected investors.

What Information Was Breached?

The notification letter states that individual investor personally identifiable information was compromised, but the version of the letter made available does not spell out the specific data elements for every recipient, since notification letters in this type of incident are often individually customized. The letter confirms that bank account numbers, income, and net worth were not included in the impacted data. Public reporting on the broader EY incident indicates that other affected clients’ notifications have referenced names, addresses, Social Security numbers, and financial account information used in tax preparation, though the specific categories that applied to Tishman Speyer investors are best confirmed through the individual notification letter itself.

What You Can Do

EY is offering affected individuals complimentary access to Experian IdentityWorks credit and identity monitoring, along with Identity Restoration services, for 24 months at no cost. Recommended precautionary steps include:

  • Enrolling in the complimentary Experian IdentityWorks credit monitoring described in your notification letter before the enrollment deadline
  • Placing a fraud alert or security freeze on your credit file with the three major credit bureaus
  • Requesting a free copy of your credit report at annualcreditreport.com and reviewing it for unfamiliar activity
  • Considering an IRS Identity Protection PIN if your Social Security number was involved
  • Reporting any suspicious account activity to your financial institution and local law enforcement

File a Data Breach Lawsuit Against Tishman Speyer

If you received a notification letter regarding this incident involving your investment holdings with Tishman Speyer, you may have legal options available to you. Companies that share investors’ sensitive financial information with outside vendors have a responsibility to ensure that information remains protected, and a breach at a vendor can carry the same real risks of identity theft and fraud as a breach at the company itself.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Between March 28, 2026, and April 12, 2026 (at vendor Ernst & Young LLP)
Date of Breach: On or about August 26, 2026
Date of Breach: On or about March 6, 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.