← Blog

Goldman Sachs Data Breaches: Full Timeline Through 2026

Share on X

People search Goldman Sachs data breach timeline because the brand sits on billions of accounts, credentials, and cloud workloads. BreachHistory indexes 4 Goldman Sachs-linked incidents, with headline counts up to 32 in catalog rows. This page maps every attested event through 2026 with internal links to canonical records.

Why Goldman Sachs breach history matters

Goldman Sachs operates in Finance (United States). Across indexed rows, recurring themes include credential theft and social engineering. Understanding the chronological pattern helps security teams, customers, and regulators separate confirmed disclosures from forum marketing.

Full timeline through 2026

2024 — unauthorized logins

Cataloged incident. Unauthorized logins to Marcus accounts via stolen credentials from elsewhere. Names, account numbers, virtual card details exposed. Exposed categories include Names, Account numbers, Credentials. No attested victim count is published for this row yet. See the gs2024 and canonical BreachHistory entry.

2018 — — Goldman Sachs: On January 11, 2018, Aperio Group, LLC, a third…

Cataloged incident. On January 11, 2018, Aperio Group, LLC, a third party investment manager used by Goldman Sachs, discovered that the email accounts of two of its employees were compromised by a sophisticated phishing attack which resulted in an unauthorized auto-forward rule being applied to those two employees' accounts. This caused all emails sent to those accounts between August 21, 2017, and January 11, 2018, to be blind copied to two external email addresses. The personal information involved in the inciden Exposed categories include Personal information. BreachHistory cites approximately 32 affected records in this row. See the goldman-sachs2018 and canonical BreachHistory entry.

2014 — — Goldman Sachs: Goldman Sachs Group Inc warned customers of a data…

Cataloged incident. Goldman Sachs Group Inc warned customers of a data breach that occured when an outside contractor emailed confidential client data to a stranger's Gmail account by mistake. The bank has asked a U.S. judge to order Google Inc to delete the email to avert a needless and massive breach of privacy.  The breach occurred on June 23 and included highly confidential brokerage account information, Goldman said in a complaint filed last Friday in a New York state court in Manhattan.Goldman Sachs di Exposed categories include Personal information. No attested victim count is published for this row yet. See the goldman-sachs2014 and canonical BreachHistory entry.

2013 — — Goldman Sachs: Bloomberg News reporters were able to monitor…

Cataloged incident. Bloomberg News reporters were able to monitor clients' usage of data terminals leased from Bloomberg LP.  Goldman Sachs is one of the companies that has complained publicly while JP Morgan Chase, the Federal Reserve, and the United States Treasury Department have started investigations. It is unclear how many other organizations may have been affected.  Reporters may have routinely retrieved login and contact information from data-services clients over the past 20 years.  Some reporters had acce Exposed categories include Personal information. No attested victim count is published for this row yet. See the goldman-sachs2013 and canonical BreachHistory entry.

Patterns and analysis

  • Credential theft and social engineering — appears across multiple Goldman Sachs catalog entries; prioritize controls that address this class of failure.
  • Record-count hygiene — BreachHistory indexes actor-cited figures separately from company-confirmed totals; read each row's technicalWriteup before treating counts as fact.
  • 2026 monitoring — New disclosures roll into this timeline as they are verified or labeled unverified per catalog policy.

What to do if you may be affected

  1. Step 1: Enable phishing-resistant MFA on every account tied to this brand.
  2. Step 2: Use unique passwords and a password manager—breach rows often involve credential reuse.
  3. Step 3: Monitor official company breach notices and regulator filings, not dark-web downloads.
  4. Step 4: Bookmark the Goldman Sachs company page for new 2026+ disclosures.

Canonical BreachHistory hub

Explore every indexed row: breachhistory.com/goldman-sachs · Latest: gs2024.

Sources: BreachHistory catalog (4 rows for Goldman Sachs), company and regulator disclosures cited in individual breach records.