Ransomware victim disclosure
← All victimsTPA Slovensko
listed as TPA Group SK · Claimed by TEAM UNDERGROUND · listed 2 days ago
Status timeline
- Listed
May 19, 2026
Current state: Listed for ransom
At a glance
- Group
- TEAM UNDERGROUND
- Status
- Listed for ransom
- Country
- Slovakia
- Sector
- Consulting
- Listed on leak site
- May 19, 2026
- Ransom demanded
- $15 million
About the victim
AI dossier — public-source company profileTPA Slovensko (tpa-group.sk) is the Slovak member firm of TPA Group, an international tax and accounting advisory network affiliated with Baker Tilly International. The firm provides tax, audit, and advisory services in Slovakia, offering tools such as a multi-country tax comparison platform (Tax-checker.com).
- Industry
- Tax & Accounting Advisory
Attack summary
Severity: medium — The post is a listing-level disclosure with a significant ransom demand ($15 million for the Slovak entity alone) against a professional tax and accounting firm, which would hold sensitive financial and client data. However, no proof files, data volume, or confirmed exfiltration details are provided, limiting severity to medium.TEAM UNDERGROUND claims to have targeted both the international TPA Group entity (tpa-group.com, valued at $281 million ransom) and TPA Slovensko (tpa-group.sk, valued at $15 million ransom); the post implies data exfiltration or encryption but provides no explicit description of data stolen or proof files.
The leak post
captured from the group's siteAll data | Underground store Data Announcements All data Afghanistan Albania Algeria American Samoa Andorra Angola Anguilla Antigua and Barbuda Argentina Armenia Aruba Australia Austria Azerbaijan Bahamas Bahrain Bangladesh Barbados Belarus Belgium Belize Benin Bermuda Bhutan Bolivia Bonaire, Sint Eustatius and Saba Bosnia and Herzegovina Botswana Brazil British Virgin Islands Brunei Darussalam Bulgaria Burkina Faso Burundi Cambodia Cameroon Canada Cape Verde Cayman Islands Central African Republic Chad Chile China Colombia Comoros Congo Congo, Democratic Republic Cook Islands Costa Rica Côte d`Ivoire Croatia Cuba Curaçao Cyprus Czech Republic Denmark Djibouti Dominica Dominican Republic East Timor Ecuador Egypt El Salvador Equatorial Guinea Eritrea Estonia Ethiopia Falkland Islands Faroe Islands Fiji Finland France French Guiana French Polynesia Gabon Gambia Georgia Germany Ghana Gibraltar Greece Greenland Grenada Guadeloupe Guam Guatemala Guinea Guinea-Bissau Guyana Haiti Honduras Hong Kong Hungary Iceland India Indonesia Iran Iraq Ireland Isle of Man Israel Italy Jamaica Japan Jordan Kazakhstan Kenya Kiribati Kuwait Kyrgyzstan Laos Latvia Lebanon Lesotho Liberia Libya Liechtenst…
Sources
Source
Indexed 2 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
