Ransomware victim disclosure
← All victimsTPA Group
Claimed by TEAM UNDERGROUND · listed 7 days ago
Status timeline
- Listed
May 14, 2026
Current state: Listed for ransom
At a glance
- Group
- TEAM UNDERGROUND
- Status
- Listed for ransom
- Country
- Austria
- Listed on leak site
- May 14, 2026
- Ransom demanded
- $281 million
About the victim
AI dossier — public-source company profileTPA Group is a professional services firm specialising in audit, legal, accounting, and tax advisory services across 12 countries in Central and South-Eastern Europe (CEE/SEE). The group operates under the domain tpa-group.com and also has a Slovak-specific entity at tpa-group.sk. It maintains numerous office locations across Austria, Poland, Romania, Czech Republic, Slovakia, and other CEE/SEE nations.
- Industry
- Audit, Tax Advisory & Legal Services
- Address
- Multiple offices across 12 countries in Central and Eastern Europe (CEE) and South-Eastern Europe (SEE), with headquarters inferred in Austria (Vienna/Wien); country offices in Albania, Bulgaria, Croatia, Montenegro, Poland, Romania, Serbia, Slovakia, Slovenia, Czech Republic, Hungary
- Employees
- 1000-5000
Attack summary
Severity: high — TPA Group is a multi-country professional services firm handling highly sensitive client financial, tax, audit, and legal data across 12 countries. A breach of this type of firm would likely involve significant regulated financial and personal data at scale, though no explicit proof of exfiltration or data volume has been published yet.TEAM UNDERGROUND claims an attack against TPA Group, demanding $281 million for tpa-group.com and an additional $15 million for tpa-group.sk. No data size or specific exfiltration details are disclosed in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Client financial records
- Tax advisory documents
- Audit files
- Legal documents
- Accounting records
The leak post
captured from the group's siteAll data | Underground store Data Announcements All data Afghanistan Albania Algeria American Samoa Andorra Angola Anguilla Antigua and Barbuda Argentina Armenia Aruba Australia Austria Azerbaijan Bahamas Bahrain Bangladesh Barbados Belarus Belgium Belize Benin Bermuda Bhutan Bolivia Bonaire, Sint Eustatius and Saba Bosnia and Herzegovina Botswana Brazil British Virgin Islands Brunei Darussalam Bulgaria Burkina Faso Burundi Cambodia Cameroon Canada Cape Verde Cayman Islands Central African Republic Chad Chile China Colombia Comoros Congo Congo, Democratic Republic Cook Islands Costa Rica Côte d`Ivoire Croatia Cuba Curaçao Cyprus Czech Republic Denmark Djibouti Dominica Dominican Republic East Timor Ecuador Egypt El Salvador Equatorial Guinea Eritrea Estonia Ethiopia Falkland Islands Faroe Islands Fiji Finland France French Guiana French Polynesia Gabon Gambia Georgia Germany Ghana Gibraltar Greece Greenland Grenada Guadeloupe Guam Guatemala Guinea Guinea-Bissau Guyana Haiti Honduras Hong Kong Hungary Iceland India Indonesia Iran Iraq Ireland Isle of Man Israel Italy Jamaica Japan Jordan Kazakhstan Kenya Kiribati Kuwait Kyrgyzstan Laos Latvia Lebanon Lesotho Liberia Libya Liechtenst…
Sources
Source
Indexed 7 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
