Ransomware victim disclosure
← All victimsMetroClub
listed as Metroclub.org · Claimed by ransomed · listed 3 years ago
Status timeline
- Listed
Oct 13, 2023
- Data leaked
At a glance
- Group
- ransomed
- Status
- Data leaked
- Country
- United States
- Sector
- Hospitality
- Listed on leak site
- Oct 13, 2023
- Data size
- 2.1 TB
About the victim
AI dossier — public-source company profileMetroClub (metroclub.org) is a private membership club based in Washington, D.C. As a private club, it likely serves professional, business, or social networking functions for its members in the D.C. area. No further verified public details are available from the site.
- Industry
- Private Members' Club & Hospitality
- Address
- Washington, D.C., United States
Attack summary
Severity: high — 2.1 TB of confirmed exfiltrated data including a full membership list and employee records from a private D.C. club constitutes significant PII exposure at scale; membership data from a private Washington D.C. club may carry additional sensitivity given the likely professional/political profile of members.The group 'ransomed' claims to have exfiltrated 2.1 TB of data from the metroclub.org website, including the complete membership list and employee data, with additional data collection reported as ongoing at the time of disclosure.
Data the group says was taken
AI dossier — extracted from the leak post- Complete membership list
- Employee records
- Full website content
The group's post references roughly 1 proof file.
What the group claims
We successfully extracted the entire content of the metroclub.org website, belonging to Metroclub, a private club based in Washington, D.C. The extracted data amounts to 2.1 terabytes. The accompanying screenshot provides a glimpse of critical information, although we are still in the process of collecting additional data. Our haul includes the complete membership list, employee…
Sources
Source
Indexed 3 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
