On November 17, 2024, the Egyptian Tax Authority (ETA) appeared on the leak site operated by the moneymessage ransomware group. The listing states that internal files were exfiltrated during a ransomware attack on the government body responsible for tax collection across Egypt. The disclosure does not specify the number of records affected or list exact data types beyond claiming that sensitive internal documents were taken.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch The Egyptian Tax Authority (ETA)
Get alerted the next time The Egyptian Tax Authority (ETA) files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about The Egyptian Tax Authority (ETA)’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details in the Leak-Site Listing
The moneymessage leak site, accessible via the onion address indexed by ransomware.live, publicly named the ETA and asserted that data had been stolen. It presents the Egyptian Tax Authority as a victim that has not yet met the group’s demands. The posting does not quantify the volume of material taken, nor does it describe the specific systems breached or the precise categories of information inside the alleged archive. Public views of the listing show only the organization name, the ransomware brand, and a statement that exfiltrated files are available for review by interested parties. No sample documents have been openly released at the time of this analysis, and the disclosure gives no deadline beyond the standard pressure tactics typical of this actor.
Why This Matters for You and Your Family
When a national tax authority loses control of internal files, the exposure can reach far beyond government offices. Tax records frequently contain full names, national identification numbers, addresses, income details, bank account information, and employer data for millions of citizens and businesses. If those details surface, identity thieves can file fraudulent returns, open accounts in your name, or combine them with other leaks to build convincing profiles. Even if your specific file is not among those published, the precedent matters: once tax agencies are successfully hit, copycat attackers target similar organizations, increasing the odds that your information will appear in a future breach. For ordinary families this translates into higher risk of tax fraud, loan scams, and persistent harassment that can last years.
The Doxxing and Identity-Chain Risks
Tax-agency data is especially dangerous because it links government identifiers to real-world addresses, phone numbers, and financial histories. Attackers routinely cross-reference such material with credential leaks, social-media handles, and gaming accounts. A single exposed national ID can anchor an identity chain that reveals family relationships, children’s names, and even school records. Credential leaks like this one often cascade into account takeovers on email, banking, and entertainment platforms. Children’s gaming accounts are particularly vulnerable because parents frequently reuse passwords or security questions derived from official documents. The result is a widening web of doxxing that can expose home addresses, family photos, and live locations. Continuous monitoring across large breach repositories is one of the few practical ways to detect these linkages before they are exploited.