The TN CPA experienced a ransomware attack by the threat actor Dragonforce, which targeted their databases and email systems, potentially compromising sensitive financial and client information. This incident underscores the cybersecurity vulnerability faced by US-based financial service providers. #United States
Incident Details
- Victim: TN CPA
- Country: US
- Actor: dragonforce
- Source: http://z3wqggtxft7id3ibr7srivv5gjof5fwg76slewnzwwakjuf3nlhukdid.onion/blog/?post_uuid=46271db4-44fd-4d2a-978d-0d9635daa2b4
- Discovered: 2025-06-17 20:22:31.944458
- Published: 2025-06-17 19:16:04.563103
Information
- Ransomware attack impacted TN CPA, a provider of financial solutions and accounting services in Texas.
- The threat actor behind the attack is dragonforce.
- The attack included access to databases and email systems.
- TN CPA offers services such as tax planning, cash flow management, part-time CFO services, and strategic business coaching.
- The firm aims to serve small business owners and high net-worth individuals.
- They focus on providing reliable bookkeeping, payroll, and tax-integrated strategies.
- The company emphasizes empowering clients with insightful data to identify financial issues and growth opportunities.

Disclaimer: This post is based on public claims made by the ransomware group "dragonforce". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.