Man Group and its applicable affiliates have notified investors that their personal information was exposed as a result of a data breach at Ernst & Young LLP, the accounting and professional services firm that provides Man Group with professional tax services. Companies that share sensitive financial and personal information with outside professional service providers have a responsibility to ensure that data remains protected, even when the breach itself occurs at a third-party vendor rather than at the company’s own systems.
Man Group’s Data Breach Investigation
Ernst & Young LLP, one of the world’s largest professional services firms, provides tax services to a wide range of financial institutions globally, including Man Group and its applicable affiliates. In the course of providing these tax services, EY received personal information relating to Man Group investors’ investment holdings. According to EY’s notification letter, sent on behalf of Man Group, an unauthorized third party accessed a support platform used by EY’s internal IT staff between approximately March 28, 2026, and April 12, 2026. EY did not detect the unauthorized activity until April 23, 2026, roughly eleven days after the intruder’s last known access.
EY has said that support tickets submitted through the compromised platform could include document attachments containing client tax information, and that the unauthorized party downloaded documents belonging to multiple EY clients during the roughly two-week access window. EY launched an investigation with the assistance of outside cybersecurity specialists to determine the scope of the incident, and notified federal law enforcement. EY submitted a breach notification to the California Attorney General on July 15, 2026, and to Vermont regulators the following day, with additional states following.
EY’s own notice to individuals leaves the specific data elements affected by any single recipient unfilled in its publicly filed sample, stating only that a recipient’s personal information affected by the incident includes an unfilled merge-field placeholder that would be completed on each individual’s actual letter. Separately, other state breach filings connected to this same EY incident have described the exposed data in more detail, including Social Security numbers, financial account information, and credit and debit account information, though EY has not confirmed that every affected individual, including those connected to Man Group, had each of these specific data types exposed.
On July 27, 2026, the ShinyHunters extortion group publicly claimed responsibility for the breach on its leak site, stating it had used a supply-chain compromise to access EY’s internal systems. EY has not confirmed that ShinyHunters was responsible for the incident, and as of the most recent public reporting, no stolen data connected to the incident had been published.
Because Man Group investors’ information reached EY only as a byproduct of the professional tax services EY provides to Man Group, those affected may never have had a direct relationship with EY themselves, yet their personal and financial information was still exposed when EY’s systems were compromised. This incident highlights a growing risk across the financial services industry: even when a company like Man Group maintains its own strong security practices, the outside professional service providers it relies on for functions like tax preparation can become a point of failure that exposes the same sensitive investor data to unauthorized access. It remains an open question whether EY maintained reasonable security measures over the compromised support platform, and whether EY and Man Group can be held accountable for the harm this incident may cause to the investors affected.
Data connected to tax preparation is particularly valuable to identity thieves because it typically combines several categories of sensitive information in one place: names, Social Security numbers, financial account details, and information about an individual’s investments and income. Unlike a compromised password, this kind of information generally cannot be reset or changed, meaning the risk of misuse can persist for years after the underlying breach occurred. Large professional services firms like EY are frequent targets for this reason, since a single successful intrusion into a shared support or document-handling platform can expose files belonging to many different clients and their investors all at once, rather than the data of a single company’s own customer base.
The roughly three-month gap between the end of the unauthorized access window in April 2026 and the first notification letters going out in July 2026 is not unusual for an incident of this scale. A thorough forensic investigation into which files were accessed, what data those files contained, and which specific individuals and organizations that data was connected to can take considerable time, particularly when the compromised platform was used across many unrelated client relationships. That does not lessen the impact on the investors ultimately affected, who were left without the opportunity to take protective steps for months after the underlying intrusion occurred.
When Did This Breach Occur?
According to EY’s notification, an unauthorized third party accessed the compromised support platform between approximately March 28, 2026, and April 12, 2026. EY detected the unauthorized activity on April 23, 2026, and began sending notification letters to affected individuals, including those connected to Man Group, starting July 13, 2026.
What Information Was Breached?
EY’s notification states that the personal information affected varies by individual and does not specify a single universal list of data categories in its publicly filed sample notice. Other state filings connected to the same underlying EY incident have referenced Social Security numbers, financial account information, and credit and debit account information as categories of data that may have been exposed, though the exact information involved for any individual connected to Man Group has not been separately confirmed.
What You Can Do
If you received a notice connecting you to this incident through your relationship with Man Group, EY is offering complimentary access to Experian IdentityWorks for 24 months. Consider enrolling before the stated deadline, since enrollment periods for this kind of offer are typically time-limited. You should also review your account and investment statements regularly for suspicious activity, consider placing a fraud alert or security freeze with the three major credit bureaus, and remain cautious of any unsolicited communications referencing this incident. Keep your notice letter, as it may serve as documentation that you were affected by this specific breach.
File a Data Breach Lawsuit Against Man Group
If your personal information was exposed as a result of this data breach, you may have legal options available to you. Companies that share sensitive investor and financial information with outside professional service providers have an obligation to ensure that data remains protected, and when that obligation isn’t met, those affected may be entitled to compensation for the harm they’ve suffered.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.