Ransomware victim disclosure
← All victimsWheelock Street Capital L.L.C.
listed as WHEELOCKST.COM · Claimed by Cl0p · listed 4 months ago
Status timeline
- ListedFeb 7, 2026
- Data leakeddate unknown
At a glance
- Group
- Cl0p
- Status
- Data leaked
- Country
- United States
- Listed on leak site
- Feb 7, 2026
About the victim
AI dossier — public-source company profileWheelock Street Capital L.L.C. is a vertically integrated private real estate investment firm founded in 2008 by Merrick R. Kleeman and Jonathan H. Paul. The firm invests across major real estate asset classes including hospitality, industrial, residential, land, and retail/mixed-use, with offices in Greenwich, CT and Boston, MA. It manages significant institutional capital and has a 15+ year track record of acquiring assets both directly and alongside partners.
- Industry
- Private Real Estate Investment & Asset Management
- Address
- 660 Steamboat Road, 3rd Floor, Greenwich, CT 06830
- Employees
- 11-50
- Founded
- 2008
Attack summary
Severity: high — Cl0p has moved to data_published status against a private real estate investment firm managing substantial institutional capital, implying confirmed exfiltration of potentially sensitive financial, investor, and transaction data. The firm handles significant institutional investor relationships and confidential deal flow, elevating severity beyond medium.Cl0p claims to have attacked Wheelock Street Capital and has moved to the data_published disclosure stage, indicating exfiltration and publication of data. No specific data volume or ransom amount has been stated, and the group's leak post content was not available for review.
Data the group says was taken
AI dossier — extracted from the leak post- Investor financial records
- Real estate transaction documents
- Institutional investor data
- Internal business communications
- Employee records
Original description
AI-summarised, not from the leak postN/A
Sources
- Victim siteWHEELOCKST.COM
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

