The Rhysida ransomware group claimed to have breached Smoll & Banning, CPAs, an accounting firm based in Dodge City, Kansas. Reports on the Daily Dark Web on November 18, 2025, state that the ransomware group listed the firm on its dark web leak site. The group demanded a ransom to prevent the sale of the stolen data.
According to the ransomware group, the allegedly compromised information includes client tax documents such as vouchers, returns, and estimated tax forms, along with personal identification details like passports and government IDs. Social Security Numbers (SSNs), Employer Identification Numbers (EINs), employee wage and tax statements (W-2s), financial spreadsheets, client contact information, and internal business documents were also reportedly stolen. The total number of affected individuals has not been publicly confirmed.
Details surrounding this incident may change as more information becomes available. Updates on regulatory notifications or official company statements have not yet been released.