> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# US Tax Service Portal Allegedly Compromised: Root SSH Access to Client Database Offered for Sale
- URL: https://darkwebinformer.com/us-tax-service-portal-allegedly-compromised-root-ssh-access-to-client-database-offered-for-sale/
- Published: 2026-01-13T18:28:55.000Z
- Updated: 2026-01-13T18:28:55.000Z
- Author: Dark Web Informer
- Tags: Initial Access

Dark Web Informer - Cyber Threat Intelligence

# US Tax Service Portal Allegedly Compromised: Root SSH Access to Client Database Offered for Sale

January 13, 2026 - 6:06:59 PM UTC 

United States 

Financial Services 

### 🧩 Standalone API Access Now Available

Access high-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more – independently from the above standard subscriptions. 

[View API Access ](https://darkwebinformer.com/api-details/) 

## Unlock Exclusive Cyber Threat Intelligence

Powered by [DarkWebInformer.com](https://darkwebinformer.com/)

Foundational access to breach intelligence. Track breaches, leaks, and threats in real time with high quality screenshots and concise expert summaries. 

📚

**5,100+ Blog Posts (PRO/ELITE)**  
Continuously updated breach reports and threat summaries.

📢

**52,200+ Alerts (PRO/ELITE)**  
Daily breach, leak, and DDoS alerts.

📤

**Unredacted Threat Feed**  
Live tracking with JSON export.

🔍

**Leak and Breach Coverage**  
Direct access to claims and posts.

📡

**Snippets and Quick Facts**  
Concise summaries of DDoS, defacements, and breaches.

🌐

**500+ Onion and Clearnet Resources**  
Verified index of dark web sites and services.

📊

**Real Time Uptime Dashboard**  
Live status of 500+ sites.

🤖

**WhiteIntel.io API**  
Integrated checks inside breach posts.

🖼️

**High Resolution Images**  
Uncompressed, watermark free evidence.

🔑

**Keyword Notifications**  
Browser alerts for tracked terms.

[💳 Subscribe Now](https://darkwebinformer.com/#/portal/signup) [🪙 Pay with Crypto](https://darkwebinformer.com/crypto-payments) 

##  Quick Facts

Date and Time of Alert

2026-01-13 18:06:59 UTC

Threat Actor

powder12

Victim Country

United States

Industry

Financial Services

Victim Org.

Unidentified US Tax Service Provider

Victim Site

Not Disclosed

Category

Initial Access

Severity

Critical

Network

Tor

##  Incident Overview

A threat actor using the handle "powder12" is offering unauthorized root SSH access to a US-based tax service server. The compromised system is described as a public website and client portal service that collects and stores sensitive client and family tax data for case processing. The company has been operating for over 15 years. 

- **Service Type:** Public website and client portal for tax case management
- **Company Operations:** 15+ years in business
- **Primary Function:** Collect client and family data/documents for tax cases, organize information, connect with responsible advisers, and prepare tax returns for submission
- **Data Collection:** Questionnaires, Social Security Numbers (SSN), income records, addresses, supporting files
- **Database Access:** All collected tax information stored in database accessible to admins/advisers for processing and preparing tax returns
- **Access Type:** SSH access with root privileges via provided user account
- **Secondary Access:** Server accessible via VNC (Virtual Network Computing)
- **Database Status:** Database not thoroughly examined by seller ("didn't look good, didn't check, I give it back as it is")
- **Pricing:** 3k$ (approximately $3,000 USD)

##  Indicators of Compromise (IOCs)

No IOCs were disclosed by the threat actor in this claim.

##  Initial Access Sale URL

For Subscribers Only 

If you are [a subscriber](https://darkwebinformer.com/tag/subscribers/), check the Threat Feed or Ransomware Feed in the subscribers area.

##  Image Preview

[ ![US tax service portal root SSH access sale by powder12 on Exploit.in containing 15+ years of client tax data](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/01/8237589826598723659872397832346235.png) ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/01/8237589826598723659872397832346235.png) 

## Unlock Exclusive Cyber Threat Intelligence

Powered by [DarkWebInformer.com](https://darkwebinformer.com/)

Foundational access to breach intelligence. Track breaches, leaks, and threats in real time with high quality screenshots and concise expert summaries. 

📚

**5,100+ Blog Posts (PRO/ELITE)**  
Continuously updated breach reports and threat summaries.

📢

**52,200+ Alerts (PRO/ELITE)**  
Daily breach, leak, and DDoS alerts.

📤

**Unredacted Threat Feed**  
Live tracking with JSON export.

🔍

**Leak and Breach Coverage**  
Direct access to claims and posts.

📡

**Snippets and Quick Facts**  
Concise summaries of DDoS, defacements, and breaches.

🌐

**500+ Onion and Clearnet Resources**  
Verified index of dark web sites and services.

📊

**Real Time Uptime Dashboard**  
Live status of 500+ sites.

🤖

**WhiteIntel.io API**  
Integrated checks inside breach posts.

🖼️

**High Resolution Images**  
Uncompressed, watermark free evidence.

🔑

**Keyword Notifications**  
Browser alerts for tracked terms.

[💳 Subscribe Now](https://darkwebinformer.com/#/portal/signup) [🪙 Pay with Crypto](https://darkwebinformer.com/crypto-payments) 

Dark Web Informer © 2026 | Cyber Threat Intelligence 

[DarkWebInformer.com](https://darkwebinformer.com/)