Ransomware victim disclosure
← All victimsThe McKee Group
listed as MCKEEGROUP.NET · Claimed by Cl0p · listed 4 months ago
Status timeline
- ListedFeb 7, 2026
- Data leakeddate unknown
At a glance
- Group
- Cl0p
- Status
- Data leaked
- Country
- United States
- Listed on leak site
- Feb 7, 2026
About the victim
AI dossier — public-source company profileThe McKee Group is a family-owned real estate development and property management company based in Springfield, Pennsylvania, with approximately 75 years of operating history. The company operates across multiple segments including commercial office leasing, residential homebuilding, apartment communities, self-storage, 55+ living villages, marina and yacht services, and car wash operations. It has received over 100 industry awards of excellence from local, regional, and national organizations.
- Industry
- Real Estate Development & Property Management
- Address
- 940 West Sproul Road, Springfield, PA 19064
- Founded
- 1949
Attack summary
Severity: medium — The disclosure status is 'data_published', suggesting some data release has occurred, but there is no detail in the leak post about the type, volume, or sensitivity of data involved; the company handles residential and commercial real estate which may include customer PII and financial records.Cl0p claims to have attacked MCKEEGROUP.NET and lists the victim under 'data_published' status, indicating data has been released; however, the leak post contains no specific details about encryption, exfiltration methods, or the nature of the data involved.
Original description
AI-summarised, not from the leak postN/A
Sources
- Victim siteMCKEEGROUP.NET
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

