Ransomware victim disclosure
← All victimsTPA Group
listed as TPA Group (.com) · Claimed by TEAM UNDERGROUND · listed 3 days ago
Status timeline
- Listed
May 18, 2026
Current state: Listed for ransom
At a glance
- Group
- TEAM UNDERGROUND
- Status
- Listed for ransom
- Listed on leak site
- May 18, 2026
- Ransom demanded
- $281 million
About the victim
AI dossier — public-source company profileTPA Group is a Central and Eastern European professional services firm offering audit, legal, accounting, and tax advisory services. The group operates across 12 countries including Austria, Poland, Romania, Slovakia, Croatia, and others in the CEE/SEE region, with dozens of office locations. It is one of the leading tax and audit firms in Central and Eastern Europe.
- Industry
- Audit, Tax Advisory & Legal Services
Attack summary
Severity: high — TPA Group is a major professional services and tax advisory firm handling sensitive financial, legal, and audit data for corporate clients across 12 countries. A successful attack would expose highly sensitive client financial and legal records at significant scale. However, no exfiltration proof or data inventory has been published, preventing a 'critical' classification.TEAM UNDERGROUND claims an attack on TPA Group's main entity (tpa-group.com) with a ransom demand of $281 million, and a separate claim against tpa-group.sk valued at $15 million; no details on encryption or exfiltration methods are provided in the post.
The leak post
captured from the group's siteAll data | Underground store Data Announcements All data Afghanistan Albania Algeria American Samoa Andorra Angola Anguilla Antigua and Barbuda Argentina Armenia Aruba Australia Austria Azerbaijan Bahamas Bahrain Bangladesh Barbados Belarus Belgium Belize Benin Bermuda Bhutan Bolivia Bonaire, Sint Eustatius and Saba Bosnia and Herzegovina Botswana Brazil British Virgin Islands Brunei Darussalam Bulgaria Burkina Faso Burundi Cambodia Cameroon Canada Cape Verde Cayman Islands Central African Republic Chad Chile China Colombia Comoros Congo Congo, Democratic Republic Cook Islands Costa Rica Côte d`Ivoire Croatia Cuba Curaçao Cyprus Czech Republic Denmark Djibouti Dominica Dominican Republic East Timor Ecuador Egypt El Salvador Equatorial Guinea Eritrea Estonia Ethiopia Falkland Islands Faroe Islands Fiji Finland France French Guiana French Polynesia Gabon Gambia Georgia Germany Ghana Gibraltar Greece Greenland Grenada Guadeloupe Guam Guatemala Guinea Guinea-Bissau Guyana Haiti Honduras Hong Kong Hungary Iceland India Indonesia Iran Iraq Ireland Isle of Man Israel Italy Jamaica Japan Jordan Kazakhstan Kenya Kiribati Kuwait Kyrgyzstan Laos Latvia Lebanon Lesotho Liberia Libya Liechtenst…
Sources
Source
Indexed 3 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
