Ransomware victim disclosure
← All victimsWEATHER.COM
Claimed by Clop · listed 5 months ago
Status timeline
- ListedJan 25, 2026
- Data leakeddate unknown
At a glance
- Group
- Clop
- Status
- Data leaked
- Country
- United States
- Sector
- Technology
- Listed on leak site
- Jan 25, 2026
About the victim
AI dossier — public-source company profileWeather.com is the digital property of The Weather Channel, one of the most visited weather websites in the United States. It provides national and local weather radar, daily forecasts, hurricane tracking, and related meteorological information to consumers and businesses. The platform is owned by The Weather Company, which was acquired by IBM and later by Allen Media Group.
- Industry
- Digital Weather & Meteorological Media
- Employees
- 1001-5000
- Founded
- 1982
Attack summary
Severity: medium — Data is marked as published, indicating some level of confirmed disclosure, but the leak post content is a redirect/queue page with no enumerated data types, no stated data volume, and no proof files visible, preventing a higher severity classification.Clop claims to have compromised Weather.com and has listed the victim with a disclosed status of data_published; the truncated leak post does not detail specific exfiltration claims or encryption activity, and no ransom amount or data size was stated.
Original description
AI-summarised, not from the leak post"Weather.com" is primarily recognized for providing comprehensive weather forecasts and information online. It is owned by IBM and forms a part of The Weather Company, offering localized forecasts for places all over the world. Besides weather updates, it furnishes weather-related news, insights, educational content, and safety tips. In addition to its web presence, the service is accessible via smartphone apps and a TV channel, The Weather Channel.
The leak post
captured from the group's siteYou have been placed in a queue, awaiting forwarding to the platform. Please do not refresh the page, you will be automatically redirected.
Sources
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

