The Egyptian Tax Authority (ETA) Listed by moneymessage Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Egyptian Tax Authority (ETA) was listed by the moneymessage ransomware group on November 17, 2024, after internal files were exfiltrated in a ransomware attack. An undisclosed number of people may have been affected; individuals are advised to check their exposure and take appropriate protective steps.
On 17 November 2024 the ransomware group known as moneymessage listed the Egyptian Tax Authority (ETA) on its leak site, claiming to have stolen internal files. For anyone who has filed taxes, registered a business, or interacted with Egypt’s tax system, the practical question is whether personal or financial records that the authority holds could now be in criminal hands. Public detail remains limited: the number of people affected is unknown and the precise contents of the files have not been independently confirmed.
What is known is that a government body responsible for collecting and administering taxes across Egypt has been named in a ransomware claim. That alone raises concrete risks of identity misuse, financial fraud, and further targeting of individuals and companies whose data may have been taken.
Inside the incident
According to the available record, moneymessage listed the Egyptian Tax Authority on 17 November 2024. The group states that internal files were exfiltrated during a ransomware attack. No further technical details—such as the initial access method, the duration of the intrusion, the volume of data taken, or any ransom demand—have been publicly disclosed. The number of individuals or organisations whose information may be involved is also unknown. The listing itself is a claim by the group; independent verification of the breach or of the data has not been reported in the facts available.
Who is moneymessage?
Moneymessage is a ransomware operation that follows the double-extortion model common among modern groups: after encrypting systems, operators also steal data and threaten to publish it if a ransom is not paid. Like other such actors, the group maintains a leak site where it posts victim names and, in some cases, samples of stolen material to pressure organisations. Public reporting on moneymessage has described it as one of several ransomware brands that emerged in the mid-2020s, typically targeting organisations with valuable internal records and using standard ransomware toolkits and negotiation tactics. No statements by the group beyond the listing of the Egyptian Tax Authority are recorded in the facts for this incident; any assertion that specific files were taken remains the group’s claim.
The Egyptian Tax Authority (ETA) and its sector
The Egyptian Tax Authority is the governmental body responsible for tax administration in Egypt. It oversees the implementation and collection of income tax, corporate tax, value-added tax (VAT) and related levies. Its work includes compliance enforcement, revenue collection, modernisation of tax procedures, and provision of services to individual and corporate taxpayers. As a central fiscal agency, the ETA necessarily processes large volumes of sensitive financial and identity information belonging to citizens, residents and businesses operating in the country. A successful intrusion into such an organisation can therefore affect not only the authority’s operations but also the privacy and financial security of the people and entities it serves. Breaches involving tax authorities are consequential because the data they hold is often highly detailed, long-lived and useful for fraud or further social-engineering attacks.
The information in question
The facts state that internal files were exfiltrated in a ransomware attack. No more specific inventory—such as taxpayer names, national identification numbers, bank details, tax returns, corporate filings or employee records—has been publicly confirmed. Organisations of this type typically hold precisely those categories of data: personal identifiers, contact information, income and asset declarations, payment histories and correspondence with taxpayers. Because the exact contents remain unconfirmed, it is not possible to state which of these, if any, were among the files claimed by moneymessage. Readers should treat any circulating samples or assertions about particular data types as unverified unless corroborated by official sources.
What's at stake
For individuals and businesses whose information may have been taken, the immediate risks include identity theft, fraudulent tax filings, phishing campaigns that exploit knowledge of real tax affairs, and unauthorised access to financial accounts. Stolen tax data can also be used to open credit lines, file false claims, or pressure people with threats of exposure. For the Egyptian Tax Authority itself, the incident raises operational concerns: potential disruption of services, the cost of investigation and recovery, and the longer-term need to restore public confidence in the confidentiality of tax records. Because the scale of the claimed exfiltration is unknown, the full extent of these risks cannot yet be measured. The listing by a ransomware group does not by itself prove that every record held by the ETA was compromised, but it does indicate that internal material was at least claimed to have left the organisation’s control.
If your data was in this claimed breach
If you have dealt with the Egyptian Tax Authority and are concerned that your information may have been involved, practical first steps can reduce the chance of harm:
- Monitor bank and credit-card statements for unexpected activity and report anomalies promptly.
- Be alert to phishing or social-engineering attempts that reference tax matters, refunds or official correspondence; verify any such contact through official channels only.
- Consider placing fraud alerts or credit freezes with relevant credit-reporting services if available in your jurisdiction.
- Change passwords on accounts that use the same credentials as any tax-related portals, and enable multi-factor authentication wherever possible.
- Keep records of any suspicious communications and report them to the appropriate Egyptian authorities or your local cybercrime unit.
You can also run a free exposure scan of your email address to check whether it has already appeared in known breach data sets. Official confirmation from the Egyptian Tax Authority, if and when it is issued, should be treated as the authoritative source on the scope of any incident.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
National Atomic Energy Commission Listed by moneymessage Ransomware GroupFamily Partnerships of Central Florida Listed by moneymessage Ransomware GroupBucks County Opportunity Council, INC. Listed by moneymessage Ransomware GroupKazyon Listed by moneymessage Ransomware GroupLatest breaches
Publicly posted by moneymessage — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.