LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Taxplan Listed by crypto24 Ransomware Group

HIGH severityUnverified claimHow we verify

Taxplan Listed by crypto24 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·April 8, 2025
Taxplan Listed by crypto24 Ransomware Group

Reported April 8, 2025.

HIGH
Severity
April 8, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Taxplan has been listed by the crypto24 ransomware group after internal files were exfiltrated in an attack, the breach was disclosed on 08 April 2025. Anyone connected to Taxplan should check whether their information was involved and follow any guidance issued by the organisation.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Ransomware groups continue to target professional services firms that handle sensitive financial records, using data theft and public leak-site listings as leverage. In this landscape, the appearance of a tax-related organisation on a known actor’s site is a signal that clients and partners should treat with caution rather than alarm.

On 8 April 2025, Taxplan was listed by the ransomware group crypto24. Public reporting states that internal files were exfiltrated in a ransomware attack and that the material includes tax-related documents and data, a database and programs. The number of people affected remains unknown, and many operational details have not been disclosed.

Inside the incident

According to the available record, Taxplan was listed by crypto24 on 8 April 2025. The group’s claim is that internal files were taken during a ransomware attack. The reported summary identifies the material as tax-related documents and data, together with a database and programs. No confirmed figure for the number of individuals affected has been published, and the precise timing of the intrusion, the initial access method, and the full scale of the compromise remain undisclosed. The listing itself constitutes an unverified claim by the threat actor; independent confirmation of every asserted detail is not present in the public facts.

Who is crypto24?

crypto24 is a ransomware operation that follows the now-common double-extortion model: encrypting systems while also exfiltrating data and threatening to publish it if a ransom is not paid. Like other groups of this type, it maintains a leak site on which it posts victim names and, in some cases, sample files or larger archives. Public reporting on crypto24 has described typical tactics that include opportunistic targeting of organisations with valuable data, use of commodity and custom tools for lateral movement, and pressure campaigns that rely on the threat of disclosure rather than encryption alone. In the present case, the only specific assertion about Taxplan is the group’s own listing; no additional claims made by crypto24 about this victim are recorded in the facts provided.

Who is Taxplan?

Taxplan operates in the tax and related professional-services sector. Organisations of this kind routinely handle client tax returns, financial statements, identity documents, correspondence with revenue authorities, and supporting databases used for compliance and advisory work. Because the data they process is both personal and financially sensitive, a breach can affect not only the firm’s own operations but also the privacy and security of clients, employees and counterparties. Public detail about Taxplan’s size, locations or specific client base is limited; what matters for risk assessment is the nature of the information such a firm typically holds.

The information in question

The facts state that internal files were exfiltrated and that the material comprises tax-related documents and data, a database and programs. Beyond that description, the exact contents, file volumes and whether any particular client or employee records were included remain unconfirmed. Firms in this sector commonly store names, addresses, tax identification numbers, income and asset details, bank information and related correspondence. Those categories represent the kinds of data that could be at risk, but they are not confirmed as present in the stolen set. Readers should therefore treat the exposure as involving sensitive tax-related material without assuming any specific record has been published.

The real-world impact

For individuals whose information may have been among the files, the primary risks are identity theft, fraudulent tax filings, phishing that leverages accurate personal details, and longer-term misuse of financial data. Because tax documents often contain government identifiers and income history, the window for abuse can extend beyond a single filing season. For Taxplan itself, the consequences include potential regulatory notification duties, client notification and support costs, reputational damage, and the operational disruption that accompanies any ransomware event. The absence of a confirmed headcount of affected people means the full scope of individual impact cannot yet be quantified; the prudent stance is to assume that anyone who has shared tax or financial records with the firm could be exposed until clearer information emerges.

What to do if you're exposed

If you have been a client or employee of Taxplan, or have reason to believe your tax-related information was held by the organisation, take the following practical steps:

You can also run a free exposure scan of your email address to check whether it has already appeared in known breach data sets. That check does not confirm or rule out involvement in this specific incident, but it provides an additional early-warning signal while further details remain limited.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyTaxplan security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See Taxplan’s full breach history →

More recent breaches

Banco Hipotecario del Uruguay Listed by crypto24 Ransomware GroupOctober 3, 2025Generali Group Listed by crypto24 Ransomware GroupSeptember 18, 2025A-Qroup Sığorta Şirkəti Listed by crypto24 Ransomware GroupJune 18, 2025Choice AG Listed by crypto24 Ransomware GroupMay 29, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Taxplan Listed by crypto24 Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by crypto24 — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram