Structab AB (MegTax) Listed by play Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Structab AB (MegTax) Listed by play Ransomware Group (reported April 18, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
On April 18, 2023, the ransomware group known as play listed Structab AB, which operates under the MegTax name, among organizations it claims to have attacked. Public reporting places the incident in Sweden. The number of people affected remains unknown, and available details state only that internal files were exfiltrated in a ransomware attack.
Because the listing comes from the group itself and independent confirmation of the full scope has not been widely detailed in the public record, the precise impact is still limited. For customers, partners, or others connected to a Swedish tax-related service provider, even an unverified claim of internal-file theft raises practical questions about what may have left the organization’s systems.
Inside the incident
According to the public record tied to the April 18, 2023 report, play added Structab AB (MegTax) to its listings and asserted that internal files had been taken during a ransomware attack. No further operational specifics—such as the initial access method, the exact date the intrusion began, the volume of data removed, or whether encryption was also deployed—have been disclosed in the facts available. The number of individuals potentially affected is likewise unknown.
Ransomware incidents of this type commonly involve both encryption of systems and theft of data for leverage, yet only the exfiltration of internal files is named here. Without additional confirmed technical detail, the incident must be understood as a claimed compromise whose full timeline and scale remain undisclosed.
Who is play?
Play is a ransomware operation that has been active in the public eye for several years. Like many contemporary groups, it typically follows a double-extortion model: encrypting victim systems while also copying data and threatening to publish it if demands are not met. The group maintains a leak site where it names organizations it claims to have breached, sometimes releasing samples or larger data sets to increase pressure.
Play has previously listed victims across multiple countries and sectors. Its public postings are claims made by the actors themselves; they are not independent forensic confirmations. In this case, the listing of Structab AB (MegTax) should be read as the group’s assertion rather than verified proof of every detail it may imply. No statements attributed to play beyond the fact of the listing and the description of internal-file exfiltration are part of the established record for this incident.
Who is Structab AB (MegTax)?
Structab AB, operating as MegTax, is a Swedish organization. Public knowledge of firms in this space indicates that MegTax-type services commonly support tax preparation, accounting, or related administrative software and processes for businesses or individuals in Sweden. Organizations of this kind routinely handle financial records, identity details, correspondence, and internal operational documents as part of normal work.
A breach affecting such a provider is consequential because the data it holds is often sensitive by nature—tax identifiers, financial figures, contact information, and internal business files. Even when the exact contents of a given incident remain unconfirmed, the sector’s typical holdings mean that any successful exfiltration can create lasting exposure for clients and for the company itself.
What data was at risk
The facts name the exposed material only as “internal files exfiltrated in ransomware attack.” No inventory of specific file types, databases, or personal-data categories has been publicly detailed. The number of people affected is unknown.
Organizations that supply tax or accounting services ordinarily store customer and client records, invoices, identification numbers, contact details, internal emails, contracts, and system configuration or backup files. It is reasonable to expect that some combination of these categories could have been present on compromised systems, yet it is not established fact that any particular category was taken. The exact contents remain unconfirmed; only the broad description of internal files is on record.
What's at stake
For individuals or businesses whose information may have been among the internal files, the practical risks include possible misuse of financial or identity data, targeted phishing that references real account or tax details, and longer-term fraud attempts. Because tax-related records often contain stable identifiers, exposure can create problems that persist well beyond the initial incident.
For Structab AB (MegTax), the stakes include operational disruption, regulatory scrutiny under Swedish and European data-protection rules, loss of client trust, and the cost of investigation and remediation. Even when a ransomware group’s claims are not fully verified, the mere public listing can damage reputation and require the organization to notify affected parties and authorities if personal data is confirmed to have been involved. Uncertainty about scope itself becomes a burden: customers cannot easily judge their own exposure, and the company must work from incomplete public information while conducting its internal review.
What to do if you're exposed
If you have used MegTax or otherwise shared information with Structab AB, treat the situation as a prompt for ordinary caution rather than panic. Monitor financial and tax-related accounts for unfamiliar activity, be skeptical of unexpected messages that reference your tax or accounting details, and consider placing fraud alerts with relevant credit or identity services if you are in a jurisdiction that offers them. Change passwords on any related accounts and enable multi-factor authentication where it is available. Keep records of any suspicious contact.
You can also run a free exposure scan of your email address to check whether it has already appeared in known breach data sets. That step will not confirm or rule out involvement in this specific incident, but it can show whether your address is circulating more widely and help you prioritize further monitoring.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
CVR Associates Listed by play Ransomware GroupOwen Quilty Professional Listed by play Ransomware GroupConcept Data Listed by play Ransomware GroupPackaging Solutions Listed by play Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Structab AB (MegTax) Listed by play Ransomware Group →
Publicly posted by play — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.