Goldman-linked EY breach highlights new era of undetectable data theft
Sensitive corporate data can be stolen through everyday workplace software without setting off traditional cyber defences, Darktrace has warned, after a breach at the Big Four giant exposed information linked to Goldman Sachs and Man Group.
Nathaniel Jones, senior vice president of global threat intelligence at Darktrace, told City AM attackers were increasingly able to hide among legitimate activity on the software businesses use every day.
“The challenge is that document theft often looks like normal business activity”, Jones said.
The warning will resonate with companies increasingly handing sensitive information to outside accountants and software providers.
A business may have secured its own network, but lose sight of the same documents once an employee uploads them elsewhere.
That is what happened in the EY incident, where neither Goldman Sachs nor Man Group’s networks were breached. Instead, the Big Four firm stored sensitive tax documents as attachments to internal IT support tickets on a platform EY used.
An unauthorised third party accessed the platform between 28 March and 12 April and downloaded documents linked to multiple EY clients, exposing information including names, addresses, email addresses, tax identification numbers, and financial details.
EY did not detect unusual activity until 23 April, 11 days after the last reported unauthorised access.
The breach“did not impact broader EY enterprise systems” and didn’t damage or present “threat to ongoing business”, said an EY spokesperson.
“EY has conducted a comprehensive review of the affected data and the investigation is now in its final stages”, they said. “We have been communicating the results of our analysis directly to clients as the review process concludes.”
“Traditional controls are good at detecting malware, exploits, or known malicious infrastructure, but they are often less effective when an attacker is using a legitimate account to browse and download files”, Jones said.
That means the tell-tale signs can be mundane, like an employee account downloading more documents than usual, accessing files belonging to different clients, logging in from an unusual location or behaving differently from its normal pattern.
The data businesses are overlooking
Jones said the bigger vulnerability is emerging as companies move more day-to-day operations onto third-party and cloud software.
“Organisations have spent years securing access to applications. The challenge is securing access to the data inside them”, he said.
“If tax documents or corporate data can be attached to tickets, organisations need visibility into where that data goes, who can access it, how long it is retained, and whether it is being downloaded at scale”.
Once sensitive information is uploaded to a supplier’s platform, he added, it can quickly move beyond the controls and monitoring that would normally protect it inside a company. That has made the seemingly unremarkable software surrounding businesses increasingly attractive to hackers.
“Attackers know this, and they are increasingly targeting operational platforms because those systems can contain high-value information without always being monitored like core production environments”, Jones said.
Goldman Sachs stressed that its own systems were unaffected and client assets remained safe.
“As with other clients we understand were affected, we have been in regular contact with EY and are focused on working with them to support any of our clients impacted by their security incident”, a spokesperson for the bank said.
Goldman’s technology risk team has since asked for “objective evidence and third-party checks” that EY’s remediation has worked.
Jones said: “Organisations want proof that remediation has worked, not simply evidence that the right processes exist on paper”.
Man Group also said the incident was “independent of Man Group’s systems, which were not compromised”.