Tishman Speyer, a global real estate development and investment firm, recently notified certain investors that their personal information was exposed as part of a data security incident at Ernst & Young LLP (EY), the accounting and professional services firm that provides Tishman Speyer with tax preparation services.
Companies that share sensitive personal and financial information with outside professional service providers have a responsibility to ensure that information remains protected, even when the exposure originates with a vendor rather than the company’s own systems.
Tishman Speyer’s Data Breach Investigation
According to a notification letter, Ernst & Young LLP provides professional tax services to a wide range of financial institutions and investment firms globally, including Tishman Speyer, and received certain personal information relating to Tishman Speyer investors’ holdings in the course of that work. EY states that its own investigation determined that an unauthorized third party accessed a third-party information technology service management platform used by EY’s IT personnel to support tax-related client work, and downloaded documents pertaining to a number of EY clients between March 28, 2026, and April 12, 2026.
EY says it confirmed the anomalous activity on April 23, 2026, and immediately activated its incident response procedures, engaging an independent cybersecurity firm and notifying federal law enforcement. On August 6, 2026, EY notified Tishman Speyer that information related to Tishman Speyer investors may have been affected by the incident. EY states it then worked to identify the specific individuals impacted, a process it describes as time-intensive given the nature of the dataset involved, and completed that process on August 25, 2026, at which point Tishman Speyer began notifying affected investors. The notification letter is explicit that Tishman Speyer’s own internal systems were not impacted by the incident; the exposure occurred entirely within EY’s third-party platform.
This incident illustrates a risk that extends well beyond any single company’s own network security: a firm can maintain excellent internal cybersecurity and still see its customers’ or investors’ information exposed because a vendor or service provider it relies on was compromised instead. Tax preparation and accounting firms like EY routinely handle highly sensitive financial documents on behalf of their clients’ own customers and investors, meaning a single vendor-side breach can ripple outward to affect people who have no direct relationship with the vendor and may not have even known their information was in the vendor’s hands.
Public reporting on this incident has noted that EY’s broader breach affected numerous clients across multiple industries, with confirmed notifications filed with state attorneys general in California, Massachusetts, Texas, and Vermont, among others, and a combined total of well over a thousand residents confirmed affected in public state filings alone. The full scope of individuals affected across all of EY’s impacted clients, including Tishman Speyer investors, has not been publicly disclosed by EY, as the company has not released a single nationwide total.
Investors and individuals whose financial or tax-related information was exposed in an incident like this face particular risk because these documents can include Social Security numbers, bank account information, and other financial identifiers that are highly valuable for identity theft, tax-refund fraud, and fraudulent account openings. The multi-month gap between the initial intrusion in the spring of 2026 and individual notifications going out in the late summer reflects the scale and complexity of determining exactly which individuals across which of EY’s many clients were affected, a process that inherently takes longer as the number of impacted organizations grows.
Tishman Speyer’s prompt notification once EY confirmed which investors were affected, and its clear statement that its own systems were not compromised, reflects appropriate handling of a vendor-side incident. Even so, affected investors deserve the same protections and support as they would in a breach originating directly with the company holding their information, which is why EY is offering credit and identity monitoring services regardless of where the exposure technically occurred.
Vendor and supply-chain breaches like this one have become an increasingly common pathway for large-scale data exposure, precisely because a single compromised service provider can sit in the data-handling chain for dozens or hundreds of separate client organizations at once. Rather than attacking each company’s investors directly, threat actors increasingly target the professional services firms, IT platforms, and support vendors that many companies rely on in common, since a single successful intrusion there can yield sensitive records belonging to a much wider set of individuals across many unrelated companies.
For Tishman Speyer investors specifically, the practical risk profile is similar to what it would be in a direct breach: the same categories of financial and personal information can end up exposed regardless of whether the point of failure was Tishman Speyer’s own systems or a vendor’s platform three steps removed. Affected investors should not assume that a vendor-side incident is inherently lower-risk than a direct breach simply because the notifying company’s own systems were not compromised.
When Did This Breach Occur?
According to the notification letter, the unauthorized access to EY’s third-party IT platform occurred between March 28, 2026, and April 12, 2026. EY detected the anomalous activity on April 23, 2026, and notified Tishman Speyer that its investors’ information may have been affected on August 6, 2026. EY completed the process of identifying the specific affected individuals and notified Tishman Speyer on August 25, 2026, after which Tishman Speyer began sending notification letters to affected investors.
What Information Was Breached?
The notification letter states that individual investor personally identifiable information was compromised, but the version of the letter made available does not spell out the specific data elements for every recipient, since notification letters in this type of incident are often individually customized. The letter confirms that bank account numbers, income, and net worth were not included in the impacted data. Public reporting on the broader EY incident indicates that other affected clients’ notifications have referenced names, addresses, Social Security numbers, and financial account information used in tax preparation, though the specific categories that applied to Tishman Speyer investors are best confirmed through the individual notification letter itself.
What You Can Do
EY is offering affected individuals complimentary access to Experian IdentityWorks credit and identity monitoring, along with Identity Restoration services, for 24 months at no cost. Recommended precautionary steps include:
- Enrolling in the complimentary Experian IdentityWorks credit monitoring described in your notification letter before the enrollment deadline
- Placing a fraud alert or security freeze on your credit file with the three major credit bureaus
- Requesting a free copy of your credit report at annualcreditreport.com and reviewing it for unfamiliar activity
- Considering an IRS Identity Protection PIN if your Social Security number was involved
- Reporting any suspicious account activity to your financial institution and local law enforcement
File a Data Breach Lawsuit Against Tishman Speyer
If you received a notification letter regarding this incident involving your investment holdings with Tishman Speyer, you may have legal options available to you. Companies that share investors’ sensitive financial information with outside vendors have a responsibility to ensure that information remains protected, and a breach at a vendor can carry the same real risks of identity theft and fraud as a breach at the company itself.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.