Gallatin Point Capital LLC is notifying individuals after an unauthorized party accessed a technology platform used by its tax provider, Ernst & Young, downloading client documents between March 28 and April 12, 2026. The exact data exposed and number of people affected have not been publicly disclosed. Affected individuals should enroll in the free credit monitoring offered and consider an IRS Identity Protection PIN.
| Company | Gallatin Point Capital LLC |
|---|---|
| Industry | Finance |
| Data Types Exposed | Personal information tied to fund investments, Tax-related documents, Social Security numbers, Other financial details |
| People Affected | Not Publicly Disclosed |
| Attack Method | Third-Party Vendor Breach |
| Regulators Notified | Not Publicly Disclosed |
Were you affected by this breach?
You may be owed compensation.
Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.
Check if you qualify — free reviewWhat Happened in the Gallatin Point Capital LLC Data Breach?
Gallatin Point Capital LLC is notifying individuals after a security incident affecting documents tied to its investment funds. The breach did not occur on Gallatin’s own systems. Instead, it originated at Ernst & Young LLP, the accounting firm that provides tax services for funds Gallatin manages.
According to the notification, EY uses a third-party technology platform to manage support tickets for its tax service teams. Those tickets sometimes contain client tax documents. An unauthorized party gained access to this platform and downloaded files between March 28, 2026, and April 12, 2026. EY says it confirmed the suspicious activity in April 2026, after which its security team opened a formal investigation.
As a result of that investigation, EY worked with an outside cybersecurity firm to confirm the intrusion had been shut down and that its systems were secure. The company also reported the incident to federal law enforcement. EY has stated it has no indication the stolen data was specifically targeted, though this does not rule out future misuse. Because the incident sat inside a vendor’s platform rather than Gallatin’s own network, three organizations are tied to this single event: Gallatin, EY, and the unnamed third-party IT vendor.
Who was affected?
The individuals affected appear to be people connected to funds or investment vehicles managed by holdings under Gallatin Point Capital LLC. Because EY serves as a tax services provider to many financial institutions, some affected people may never have interacted with Gallatin directly. This is common in vendor-related breaches, where exposure reaches investors indirectly through a service provider relationship.
The exact number of people affected has not been publicly disclosed. The notification letter posted by Massachusetts regulators is a template, and the field for the total count of impacted residents was left blank. In addition, the letter references credit monitoring tied to an individual whose Social Security number may have been used to establish an entity. This detail suggests some records relate to investment entities, not just individual consumers, though this has not been confirmed in detail.
What Information Was Potentially Exposed?
The specific data elements involved for any single person have not been made public. The posted notice is a template, and the section meant to list exposed information categories was left blank. However, based on the nature of EY’s work and references within the letter, certain categories can reasonably be described.
- Personal information tied to investments in Gallatin-managed funds
- Tax-related documents handled by EY on behalf of clients
- Social Security numbers, referenced specifically regarding entity formation
- Other financial details potentially included in client tax files
Because tax documents often contain detailed financial histories, any exposure in this category carries real risk. For example, tax filings can include income figures, account numbers, and identifying details beyond a name and address. This combination gives criminals more than enough material to attempt fraud.
In addition, when Social Security numbers are involved, the risk extends beyond simple scams. Thieves can use these numbers to open credit lines, file fraudulent tax returns, or impersonate victims in official filings. Because the letter specifically mentions an IRS Identity Protection PIN program, it appears EY itself recognizes this tax fraud risk as a genuine concern for at least some recipients.
What is the company doing?
EY says it immediately activated its incident response process once it confirmed the anomalous platform activity. As a result, the company contained the intrusion and brought in an independent cybersecurity firm to verify that systems were secured. EY also notified federal law enforcement about the incident, a step that often happens when sensitive financial or tax data is involved.
Beyond containment, EY is offering affected individuals complimentary enrollment in Experian’s IdentityWorks credit and identity monitoring, along with Identity Restoration services, for a 24-month period. The letter also directs recipients to the IRS Identity Protection PIN program, which helps block fraudulent tax filings made using a stolen Social Security number. The company filed notice of this incident with the Massachusetts Attorney General’s Office as part of its regulatory obligations.
What Should Affected Individuals Do?
Review Your Notification Letter Carefully
If you received a letter about the Gallatin Point Capital LLC data breach, read it in full and keep it somewhere safe. It is the most specific source of information about what data applies to your situation. Because the publicly posted version is a blank template, your personal copy may include details not available anywhere else.
In addition, keep any enrollment codes or deadlines mentioned in your letter. These codes are often required to activate free monitoring services. Losing this information could mean missing your window to enroll in protection at no cost.
Place a Fraud Alert or Credit Freeze
Because Social Security numbers may be involved for at least some individuals, consider placing a credit freeze with Equifax, Experian, and TransUnion. A freeze blocks new creditors from accessing your credit file, which makes it much harder for someone to open accounts in your name. This step is free and can be lifted temporarily whenever you need to apply for credit yourself.
Alternatively, a fraud alert requires creditors to verify your identity before extending new credit. This option is faster to set up but offers slightly less protection than a full freeze. Either way, acting early reduces the window of opportunity for criminals.
Guard Against Tax-Related Identity Theft
Because tax documents were involved in this incident, affected individuals should consider enrolling in the IRS Identity Protection PIN program. This program issues a six-digit code that must be included on any tax return filed under your Social Security number. As a result, it becomes far more difficult for someone else to file a fraudulent return in your name.
It is also wise to file your taxes as early as possible each year going forward. Fraudulent returns often succeed because scammers file before the real taxpayer does. Filing early closes that opportunity.
Monitor Accounts and Watch for Phishing
Check your financial accounts, tax records, and any insurance statements regularly for unfamiliar activity. Because this breach touched tax-related documents, watch closely for notices from the IRS about returns you did not file. Report anything suspicious right away to limit potential damage.
Furthermore, be cautious of unexpected calls, texts, or emails referencing this breach, Gallatin, or EY. Scammers often use real breach news to craft convincing phishing attempts. Never click links or share personal details unless you can verify the sender independently.
Consider Your Legal Options
If your information was exposed in this breach, you may have grounds to pursue compensation through legal action. Companies entrusted with sensitive tax and financial data are expected to protect it with reasonable safeguards. When that protection fails, affected individuals often have the right to seek accountability.
Speaking with a data breach attorney can help clarify whether you qualify to join a claim related to this incident. Many offer free consultations, so there is little risk in simply asking questions about your options. This is especially worth considering if you later discover signs of identity theft or tax fraud.
Get a Free Case Review
Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.
