Were you recently affected by a data breach?

Man Group Data Breach

Man Group investors were notified that their personal information was exposed when a support platform used by Ernst & Young, the firm’s tax services provider, was breached by an unauthorized party.

Man Group
Date of Breach: March 28 - April 12, 2026
CAU logo

Who was affected:

Clients of Man Group

Impacted Data:

Personal information varies by individual; related state filings reference Social Security numbers, financial account information, and credit and debit account information

Man Group and its applicable affiliates have notified investors that their personal information was exposed as a result of a data breach at Ernst & Young LLP, the accounting and professional services firm that provides Man Group with professional tax services. Companies that share sensitive financial and personal information with outside professional service providers have a responsibility to ensure that data remains protected, even when the breach itself occurs at a third-party vendor rather than at the company’s own systems.

Man Group’s Data Breach Investigation

Ernst & Young LLP, one of the world’s largest professional services firms, provides tax services to a wide range of financial institutions globally, including Man Group and its applicable affiliates. In the course of providing these tax services, EY received personal information relating to Man Group investors’ investment holdings. According to EY’s notification letter, sent on behalf of Man Group, an unauthorized third party accessed a support platform used by EY’s internal IT staff between approximately March 28, 2026, and April 12, 2026. EY did not detect the unauthorized activity until April 23, 2026, roughly eleven days after the intruder’s last known access.

EY has said that support tickets submitted through the compromised platform could include document attachments containing client tax information, and that the unauthorized party downloaded documents belonging to multiple EY clients during the roughly two-week access window. EY launched an investigation with the assistance of outside cybersecurity specialists to determine the scope of the incident, and notified federal law enforcement. EY submitted a breach notification to the California Attorney General on July 15, 2026, and to Vermont regulators the following day, with additional states following.

EY’s own notice to individuals leaves the specific data elements affected by any single recipient unfilled in its publicly filed sample, stating only that a recipient’s personal information affected by the incident includes an unfilled merge-field placeholder that would be completed on each individual’s actual letter. Separately, other state breach filings connected to this same EY incident have described the exposed data in more detail, including Social Security numbers, financial account information, and credit and debit account information, though EY has not confirmed that every affected individual, including those connected to Man Group, had each of these specific data types exposed.

On July 27, 2026, the ShinyHunters extortion group publicly claimed responsibility for the breach on its leak site, stating it had used a supply-chain compromise to access EY’s internal systems. EY has not confirmed that ShinyHunters was responsible for the incident, and as of the most recent public reporting, no stolen data connected to the incident had been published.

Because Man Group investors’ information reached EY only as a byproduct of the professional tax services EY provides to Man Group, those affected may never have had a direct relationship with EY themselves, yet their personal and financial information was still exposed when EY’s systems were compromised. This incident highlights a growing risk across the financial services industry: even when a company like Man Group maintains its own strong security practices, the outside professional service providers it relies on for functions like tax preparation can become a point of failure that exposes the same sensitive investor data to unauthorized access. It remains an open question whether EY maintained reasonable security measures over the compromised support platform, and whether EY and Man Group can be held accountable for the harm this incident may cause to the investors affected.

Data connected to tax preparation is particularly valuable to identity thieves because it typically combines several categories of sensitive information in one place: names, Social Security numbers, financial account details, and information about an individual’s investments and income. Unlike a compromised password, this kind of information generally cannot be reset or changed, meaning the risk of misuse can persist for years after the underlying breach occurred. Large professional services firms like EY are frequent targets for this reason, since a single successful intrusion into a shared support or document-handling platform can expose files belonging to many different clients and their investors all at once, rather than the data of a single company’s own customer base.

The roughly three-month gap between the end of the unauthorized access window in April 2026 and the first notification letters going out in July 2026 is not unusual for an incident of this scale. A thorough forensic investigation into which files were accessed, what data those files contained, and which specific individuals and organizations that data was connected to can take considerable time, particularly when the compromised platform was used across many unrelated client relationships. That does not lessen the impact on the investors ultimately affected, who were left without the opportunity to take protective steps for months after the underlying intrusion occurred.

When Did This Breach Occur?

According to EY’s notification, an unauthorized third party accessed the compromised support platform between approximately March 28, 2026, and April 12, 2026. EY detected the unauthorized activity on April 23, 2026, and began sending notification letters to affected individuals, including those connected to Man Group, starting July 13, 2026.

What Information Was Breached?

EY’s notification states that the personal information affected varies by individual and does not specify a single universal list of data categories in its publicly filed sample notice. Other state filings connected to the same underlying EY incident have referenced Social Security numbers, financial account information, and credit and debit account information as categories of data that may have been exposed, though the exact information involved for any individual connected to Man Group has not been separately confirmed.

What You Can Do

If you received a notice connecting you to this incident through your relationship with Man Group, EY is offering complimentary access to Experian IdentityWorks for 24 months. Consider enrolling before the stated deadline, since enrollment periods for this kind of offer are typically time-limited. You should also review your account and investment statements regularly for suspicious activity, consider placing a fraud alert or security freeze with the three major credit bureaus, and remain cautious of any unsolicited communications referencing this incident. Keep your notice letter, as it may serve as documentation that you were affected by this specific breach.

File a Data Breach Lawsuit Against Man Group

If your personal information was exposed as a result of this data breach, you may have legal options available to you. Companies that share sensitive investor and financial information with outside professional service providers have an obligation to ensure that data remains protected, and when that obligation isn’t met, those affected may be entitled to compensation for the harm they’ve suffered.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: January 28 - February 4, 2026
Date of Breach: On or around August 18, 2026
Date of Breach: Not publicly disclosed (notification letter dated September 23, 2026)
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.