Ransomware victim disclosure
← All victimsNorthBridge Partners
listed as Northbridge · Claimed by Play · listed 4 months ago
Status timeline
- ListedFeb 11, 2026
- Data leakeddate unknown
At a glance
- Group
- Play
- Status
- Data leaked
- Country
- United States
- Listed on leak site
- Feb 11, 2026
About the victim
AI dossier — public-source company profileNorthBridge Partners is a private real estate investment firm and operator headquartered in Wakefield, Massachusetts, focused on acquiring, modernizing, and managing infill logistics and warehouse properties across the United States. The firm manages over $3.1 billion in assets under management spanning approximately 12.5 million square feet across 12 states. NorthBridge operates a vertically integrated platform targeting small-to-mid-sized industrial assets near dense population centers to serve e-commerce, high-tech manufacturing, and last-mile delivery demand.
- Industry
- Private Real Estate Investment & Industrial Logistics
- Address
- 401 Edgewater Place, Suite 430, Wakefield, MA 01880
- Employees
- 51-200
- Founded
- 2015
Attack summary
Severity: high — Data has been confirmed as published by a known ransomware group. NorthBridge manages $3.1B+ in real estate assets with institutional investors (e.g., NY Common, LACERS), meaning exfiltrated data likely includes sensitive financial, investor PII, and proprietary deal/asset information at significant scale.The Play ransomware group claims to have attacked NorthBridge and has published data (disclosed status: data_published), indicating exfiltration of company data. No specific ransom amount or data size has been stated in the leak post.
Data the group says was taken
AI dossier — extracted from the leak post- Company internal documents
- Investor records
- Financial data
- Real estate transaction data
- Employee information
What the group claims
United States
The leak post
captured from the group's site| Play ransomware HAS NEVER PROVIDED AND DOES NOT PROVIDE THE RaaS, read the FAQ page.WE NEVER WRITES FIRST, IF SOMEONE WRITES TO YOU, THEY ARE SCAMMERS.we'll buy your access: 75tkvxemb6zpyk3fbl3mwm32jklc2sdjacb3kazrioamopbfn2w2z5qd.onionIf we have not responded to you by email within 12 hours, please leave your contact information on the website in the contact tab. | | --- | | EMA Engineering & Consulting👁️ views: 321added: 2026-05-07publication date: 2026-05-11 | Accessoires Outillage Ltee👁️ views: 280added: 2026-05-07publication date: 2026-05-11 | K & E Distributing👁️ views: 282added: 2026-05-07publication date: 2026-05-11 | | Sokolin👁️ views: 7261 | Barnes Solicitors LLP👁️ views: 7182 | Witt UK Group👁️ views: 8181 | | Valley Plating Inc👁️ views: 8198 | Dock Pros👁️ views: 8179 | Kivells👁️ views: 8149 | | Specflue👁️ views: 8136 | Weber Kracht & Chellew👁️ views: 8180 | Lucky Look👁️ views: 8285 |
Sources
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

