On April 3, 2026, Austrian tax consulting firm Tscherne Consulting Steuerberatung GmbH appeared on the leak site of the ransomware group Payload. The Graz-based company, which handles bookkeeping, tax planning, payroll processing, and business consulting for small and medium-sized businesses, had internal files exfiltrated during a ransomware attack. While the exact number of individuals whose personal or financial data may have been exposed remains unknown, anyone who has worked with the firm — as a client, employee, or vendor — may now be at risk.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Tscherne Consulting Steuerberatung GmbH
Get alerted the next time Tscherne Consulting Steuerberatung GmbH files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Tscherne Consulting Steuerberatung GmbH’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that Payload posted details of the Tscherne Consulting breach on its dark-web leak site. The Austrian tax advisor specializes in services for smaller companies, meaning the stolen files likely contain sensitive financial records, tax returns, payroll data, and correspondence that often include names, addresses, tax identification numbers, and banking details. No confirmed timeline of the initial intrusion has been released, but the listing on April 3, 2026, signals that negotiations between the attackers and the firm had either failed or reached a deadline.
Internal files were allegedly exfiltrated, a common ransomware tactic designed to pressure victims into paying to prevent public release. Available reporting describes the data as business-related documents rather than a simple database dump, which increases the potential for identity theft or targeted fraud against both the company and the individuals named in those records.
Why This Matters for You and Your Family
If you or anyone in your household has ever used Tscherne Consulting Steuerberatung GmbH for tax advice, payroll, or bookkeeping, your personal information may now sit in a ransomware leak repository. Tax documents frequently contain your full name, date of birth, address, social security or tax ID number, income details, and bank account information — exactly the data thieves need to file fraudulent tax returns, open accounts in your name, or impersonate you to creditors.