On July 21, 2026, the ransomware group known as Play added Tax MT to its public leak site, listing the United States-based tax preparation firm as a victim of a ransomware attack in which internal files were exfiltrated.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Tax MT
Get alerted the next time Tax MT files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Tax MT’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details from the Leak Site
The primary disclosure comes directly from the Play ransomware leak site, accessible via the onion link hosted on ransomware.live. The listing states that Tax MT suffered a ransomware incident during which attackers exfiltrated internal files. The notification does not quantify the number of affected records, specify the exact data types beyond “internal files,” or disclose the ransom demand. It simply marks the company as having been compromised and publishes proof of the exfiltration. No formal breach notification from Tax MT itself has surfaced publicly at the time of this writing, leaving many specifics unknown.
Why This Matters for You and Your Family
When a tax preparation firm is breached, the exposure often reaches deep into personal financial lives. Tax documents typically contain Social Security numbers, dates of birth, addresses, income details, and banking information for individuals and families who used the service. Even though the exact volume of data is not stated, the internal files taken are almost certain to include client records. For ordinary people, this means your most sensitive yearly financial snapshot may now be in the hands of criminals who specialize in extortion. Your family’s tax returns may be leveraged for identity theft, fraudulent filings, or sold quietly on underground markets long after the initial headline fades.
The Doxxing and Identity-Chain Risk
Ransomware leaks like this one rarely stop at the corporate perimeter. Once internal files leave the victim’s network, attackers or subsequent buyers can map relationships between names, addresses, Social Security numbers, and email accounts. These linkages create doxxing chains that connect your tax identity to online handles, gaming accounts, and family members. A single exposed tax record can seed years of targeted phishing, account takeovers, and even physical stalking if home addresses are published. Credential leaks that surface in these datasets frequently cascade into gaming platforms, where children’s accounts become entry points for further harassment or theft because the same password or email was reused.