Ransomware victim disclosure
← All victimsThe McKee Group
listed as MCKEEGROUP.NET · Claimed by Clop · listed 4 months ago
Status timeline
- ListedFeb 7, 2026
- Data leakeddate unknown
At a glance
- Group
- Clop
- Status
- Data leaked
- Country
- United States
- Listed on leak site
- Feb 7, 2026
About the victim
AI dossier — public-source company profileThe McKee Group is a family-owned real estate development and property management conglomerate headquartered in Springfield, Pennsylvania, with over 75 years of operating history. The company operates a diverse portfolio of businesses spanning office properties, residential homebuilding, apartment communities, self-storage facilities, 55+ living villages, a marina and yacht sales operation, and a car wash venture. It is based in Delaware County, Pennsylvania, and has received more than 100 industry awards of excellence.
- Industry
- Real Estate Development & Property Management
- Address
- 940 West Sproul Road, Springfield, PA 19064
Attack summary
Severity: high — Clop has published the data (disclosed status: data_published), indicating confirmed exfiltration rather than a mere listing. The company operates across multiple business lines with employee, customer, and financial data at risk. While no regulated medical or government data is evident, the breadth of the organisation and confirmed publication elevates this to high severity.The Clop ransomware group claims to have compromised The McKee Group and lists the disclosure status as data_published, indicating data exfiltration and publication. The leak post itself provided no detail on the nature or volume of data stolen beyond the group's standard queue-redirect mechanism.
Data the group says was taken
AI dossier — extracted from the leak post- Corporate business data
- Employee records (possible via Employee Portal)
- Customer/resident information
- Real estate and property documents
- Financial records
Original description
AI-summarised, not from the leak postN/A
The leak post
captured from the group's siteYou have been placed in a queue, awaiting forwarding to the platform. Please do not refresh the page, you will be automatically redirected.
Sources
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

