Ransomware victim disclosure
← All victimsWealth Enhancement Group
Claimed by Raworld · listed 3 years ago
Status timeline
- ListedMay 6, 2023
- Data leakeddate unknown
At a glance
- Group
- Raworld
- Status
- Data leaked
- Country
- United States
- Sector
- Financial
- Listed on leak site
- May 6, 2023
About the victim
AI dossier — public-source company profileWealth Enhancement Group is a large US-based registered investment advisory (RIA) firm offering comprehensive wealth management services including investment management, tax strategies, estate planning, retirement income planning, and risk management. The firm operates a team-based 'Roundtable' model pairing local advisor teams with specialists, and has been recognized by Barron's as one of the top RIA firms in the country. It serves individual clients, families, and businesses across multiple locations in the United States.
- Industry
- Registered Investment Advisory & Wealth Management
- Employees
- 1001-5000
Attack summary
Severity: critical — Wealth Enhancement Group manages comprehensive financial and tax data for thousands of high-net-worth individuals and businesses. A confirmed data publication by a ransomware group against a major RIA almost certainly involves regulated financial PII, tax records, and investment data at significant scale, meeting the critical threshold for exfiltration of sensitive regulated financial data.The raworld ransomware group claims to have attacked Wealth Enhancement Group and lists the disclosure status as data_published, indicating exfiltration and/or publication of data. No specific details about the volume or type of data, ransom demand, or encryption were captured in the leak post.
Data the group says was taken
AI dossier — extracted from the leak post- Client financial records
- Personal identifying information (PII)
- Tax planning documents
- Retirement account data
- Estate planning documents
- Investment portfolio data
- Employee records
Sources
Source
Indexed 3 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

