Were you recently affected by a data breach?

Gallatin Point Capital LLC Data Breach

Ernst & Young LLP is notifying people whose information it held as a tax services provider for funds managed by Gallatin Point Capital LLC. EY says an unauthorized party downloaded documents between March 28, 2026 and April 12, 2026.

Gallatin Point Capital LLC
Date of Breach: March 28, 2026 to April 12, 2026
CAU logo

Who was affected:

Clients of Gallatin Point Capital LLC

Impacted Data:

Not publicly disclosed. The posted notice letter template leaves the list of affected data elements blank.

Gallatin Point Capital LLC is named in a data breach notification posted in Massachusetts’ list of notification letters for October 2026. The notice was issued by Ernst & Young LLP (EY), which says it provided the notice on Gallatin’s behalf after an incident on an EY platform.

If you received this notice, here is what has been made public so far and what you can do about it.

Gallatin Point Capital LLC’s Data Breach Investigation

The letter is signed by EY, not by Gallatin. EY explains that it provides professional tax services to a wide range of financial institutions around the world. In the course of that work, it received certain personal information relating to people’s investment in one or more funds or investment vehicles managed by holdings with Gallatin Point Capital LLC. The letter states that the incident occurred on an EY platform and did not involve Gallatin’s systems.

According to the letter, EY uses a third-party information technology service management platform to help its technology staff support the teams that perform tax work for clients. Support tickets submitted through that platform may include documents containing client tax information. EY says it confirmed anomalous activity within that platform on April 23, 2026, and that its information security team immediately started its incident response procedure to determine the nature and scope of the incident, contain it and begin recovery.

EY says that, based on its investigation and the evidence available, an unauthorized third party accessed the platform between March 28, 2026 and April 12, 2026 and downloaded documents pertaining to a number of EY clients. It says it worked with an independent cybersecurity firm to confirm that the unauthorized access has been stopped and that its systems are now secure. EY also says it notified federal law enforcement and that it has no indication that the information was specifically targeted.

As posted by the state, the letter is a template. The places where the specific information involved, the enrollment deadline, the activation code and the number of residents of certain states would be filled in are blank. This page therefore does not say which categories of information were involved for any individual and does not guess. The letter does mention that credit monitoring is offered for the individual whose Social Security number may have been used to establish an entity, which suggests that some of the affected records relate to investment entities rather than people, though the letter does not spell that out.

EY is offering complimentary access to two Experian products, IdentityWorks credit and identity monitoring and Identity Restoration, as a 24-month membership. The letter also points readers to the Internal Revenue Service Identity Protection PIN program, which gives eligible people a six-digit number that helps prevent someone else from filing a tax return with their Social Security number.

What the notice does not give is a total. We did not find the number of people affected in the Massachusetts listing or in a press statement, so this page does not state a count. It also does not say who was responsible for the incident, and the template’s per-state resident numbers are blank.

Because the notice reaches people through an intermediary, the names can be confusing. The state lists the filing under Gallatin Point Capital LLC, the letter is signed by EY, and the incident happened on a platform run by a third-party vendor to EY. Three different organizations are involved, and the letter says the incident did not involve Gallatin’s systems. Keep the envelope and any enrollment details together in case you need them later.

Tax advisers and other professional service firms hold detailed financial documents for many clients at once, which makes them attractive to attackers. A breach at a service provider can reach people who never dealt with that provider directly, such as investors in a fund. We are describing the general landscape only. The letter does not say that any of the information has been misused.

If you received a letter, read it closely and keep a copy. It is the best source for what applies to you. If you think you may be affected but did not receive anything, you can contact EY at the number listed in the letter, or Gallatin Point Capital LLC, to ask whether your information was involved.

When Did This Breach Occur?

The letter states that EY confirmed anomalous activity within the platform on April 23, 2026, and that an unauthorized third party accessed the platform between March 28, 2026 and April 12, 2026.

The letter does not give a mailing date. The gap between the access window and the date EY confirmed the activity is a reminder that the confirmation date and the date of exposure can be weeks apart.

What Information Was Breached?

The posted copy of the letter says the information relating to the recipient was involved, but the list of specific data elements is a blank template field. EY says it received personal information relating to people’s investments in funds managed by Gallatin and that the documents downloaded pertain to a number of EY clients.

The letter refers to Social Security numbers in the context of credit monitoring for an individual whose number may have been used to establish an entity. It does not confirm which items were involved for any particular person, so your own notice letter is the best source.

What You Can Do

If you received a notice from Gallatin Point Capital LLC or believe you may be affected, consider these steps:

  • Read the notice carefully and keep it, along with any enrollment details for protection services it offers.
  • Place a free fraud alert or a credit freeze with Equifax, Experian and TransUnion, and get your reports free at annualcreditreport.com.
  • Watch your financial accounts, tax records and any insurance or medical statements for activity you do not recognize.
  • Be skeptical of unexpected calls, texts or emails that mention the organization, and report suspected identity theft to the Federal Trade Commission at identitytheft.gov and to your state Attorney General.

File a Data Breach Lawsuit Against Gallatin Point Capital LLC

If your personal information may have been exposed in this incident, you may have legal options. Organizations that hold sensitive financial and tax information are expected to safeguard it, and a class action can help hold them accountable when it fails to do so.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: March 28, 2026 to April 12, 2026
Date of Breach: Discovered October 7, 2026
Date of Breach: Not publicly disclosed (discovered September 9, 2026)
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.