Data Breach Watch logoDBW
    Other
    Low
    monitoring
    Updated about 1 month ago

    Smoll & Banning, CPAs Data Breach

    Key takeaways

    • Reports suggest a potential breach involving Smoll & Banning, CPAs.
    • Discovered on May 31, 2026.
    • Possible data exposed: Client Tax Documents (Vouchers, Returns, and Estimated Tax Forms), Personal Identification Documents (Passports and Government IDs), Social Security Numbers (SSNs), Employer Identification Numbers (EINs), Employee Wage and Tax Statements (W-2s), Financial Spreadsheets (Ledgers, Actuals, and Payroll Logs), Client Contact Information (Full Names and Addresses), Internal Business Documents (Client Lists and Correspondence).
    • Affects individuals in: Kansas.
    • Confirmation level: Based on reports.

    Detailed summary

    The Rhysida ransomware group claimed to have breached Smoll & Banning, CPAs, an accounting firm based in Dodge City, Kansas. Reports on the Daily Dark Web on November 18, 2025, state that the ransomware group listed the firm on its dark web leak site. The group demanded a ransom to prevent the sale of the stolen data.

    According to the ransomware group, the allegedly compromised information includes client tax documents such as vouchers, returns, and estimated tax forms, along with personal identification details like passports and government IDs. Social Security Numbers (SSNs), Employer Identification Numbers (EINs), employee wage and tax statements (W-2s), financial spreadsheets, client contact information, and internal business documents were also reportedly stolen. The total number of affected individuals has not been publicly confirmed.

    Details surrounding this incident may change as more information becomes available. Updates on regulatory notifications or official company statements have not yet been released.

    Data possibly involved

    • Client Tax Documents (Vouchers, Returns, and Estimated Tax Forms)
    • Personal Identification Documents (Passports and Government IDs)
    • Social Security Numbers (SSNs)
      Can be used to open fraudulent accounts and file false tax returns
    • Employer Identification Numbers (EINs)
    • Employee Wage and Tax Statements (W-2s)
    • Financial Spreadsheets (Ledgers, Actuals, and Payroll Logs)
    • Client Contact Information (Full Names and Addresses)
      Could be combined with other data for identity theft
    • Internal Business Documents (Client Lists and Correspondence)

    Company Response Timeline

    Response Grade
    F

    Took over 180 days or has not yet notified consumers

    Breach Occurred

    Nov 18, 2025

    Company Discovered

    Nov 18, 2025

    Regulator Notified

    Unknown

    Consumers Notified

    Unknown

    0 days to discover

    Breach Verification Status

    Reports Only

    Current

    Initial dark web reports of potential breach

    Company Confirmed

    Company has acknowledged the breach

    Regulator Confirmed

    Confirmed by regulatory authorities

    Note: Breach verification can take time. Information may evolve as more details become available from companies and regulators.

    Case Status:
    Monitoring

    We're monitoring this situation for developments.

    Were You Affected By This Breach?

    If you are a customer or have received a data breach notification, you may submit your information as part of our ongoing investigation. Submitting your information is free and does not obligate you.

    Were you in the Smoll & Banning, CPAs breach? Check your email

    Free scan against known breach datasets. Then remove your info from data-broker sites with Data Shield.

    No signup required. 30-second scan. Your email is only stored if you opt into alerts.

    Get your info off data-broker sites

    Data Shield files removal requests with every broker that accepts an authorized agent, and gives you the exact link or letter for the brokers that only accept requests from you.

    See how Data Shield works

    Check Your Risk Level

    Answer a few questions to understand how this breach might affect you

    What should I do?

    Change your passwords

    Update passwords for the affected service and any accounts using the same password

    Enable two-factor authentication

    Add an extra layer of security to your accounts

    Monitor your accounts

    Watch for suspicious activity on your financial and online accounts

    Watch for phishing attempts

    Be cautious of emails or messages claiming to be from the affected company

    Consider a credit freeze

    Prevent unauthorized access to your credit report

    Scan your email for other exposures

    Check whether this address shows up in other known breaches. Free, no account.

    Get your info off data-broker sites

    Data Shield files removal requests with every broker that accepts an authorized agent, and gives you the exact link or letter for the brokers that only accept requests from you.

    See how Data Shield works

    Got a notice about this breach?

    Paste it into BreachBrief to see exactly what data was exposed, how serious it is, and what to do next.

    Protect yourself

    Share This Breach Alert

    Help friends and family who might be affected by sharing this breach information

    Are you a law firm investigating this breach?

    Get qualified claimant leads delivered directly to your CRM.

    Related breaches

    Stay informed about breaches like this one

    We'll notify you when new data breaches are reported. Free, no spam. Unsubscribe anytime.

    Free, no spam. Unsubscribe anytime.