Goldman Sachs said during 2025 that some client data may have been exposed in a breach at a third party.
The Bank Is The Name In The Headline And Not The Organisation Breached
This corpus has recorded the pattern repeatedly: Marquis reaching customers of 74 institutions at 25-0814, SitusAMC holding records for major banks at 25-1112b, a procurement platform holding nineteen organisations’ staff directories at 25-0613.
A client reads that their bank has had a breach. The bank’s systems were not compromised. Both statements are true, and the second one is the one that determines what could have been prevented and by whom.
"May Have Been" Is The Honest Formulation And It Is Unsatisfying
The corpus criticised "no evidence of misuse" at 25-1219 as technically accurate and unearned, because identification is impossible.
"May have been exposed" is the opposite error in the same family — an organisation reporting what it cannot rule out rather than what it has established, because a third party holds the evidence.
The layered notification problem at 25-1027 explains why. A downstream institution learns from its supplier, on the supplier’s timetable, with the supplier’s scope determination. It is reporting somebody else’s investigation.
And It Is The Sector With The Strongest Supervision
This desk filed at 25-0616 that financial institutions carry the densest regulatory obligations of any commercial sector and record the highest average breach cost largely because of them.
None of that supervision reached the third party. DORA at 25-0117 is the one instrument in this corpus that extends to critical ICT providers, and it applies in the EU. Graded medium: the incident is thinly reported and the third party is not named in the material we reviewed.
Compiled from published reporting, listed below. The third party is not named, and the affected volume is not established. Corrections: corrections@forensicpost.com.