Ransomware victim disclosure
← All victimsClearway Group
listed as CLEARWAYGROUP.COM · Claimed by Clop · listed 5 months ago
Status timeline
- ListedJan 25, 2026
- Data leakeddate unknown
At a glance
- Group
- Clop
- Status
- Data leaked
- Country
- Hong Kong SAR China
- Listed on leak site
- Jan 25, 2026
About the victim
AI dossier — public-source company profileClearway Group is one of Canada's largest construction companies, headquartered in Maple, Ontario. The company originated as a sewer and watermain contractor and has expanded into utilities, general construction, and haulage through divisions including Clearway Utilities, Clearway Construction, and Sterling Haulage. It operates across multiple construction disciplines and maintains partnerships with firms such as Signature Communities and SYNRG Group.
- Industry
- Construction & Civil Infrastructure
- Address
- 45 Rodinea Road, Suite C, Maple, ON L6A1R3, Canada
Attack summary
Severity: high — Clop is a sophisticated ransomware group with a documented history of large-scale data exfiltration; the status is marked 'data_published', indicating confirmed data release. Clearway Group is described as one of Canada's largest construction companies, suggesting significant business and potentially sensitive contractual/financial data is at risk. No regulated PII at scale is confirmed, keeping this at high rather than critical.Clop claims to have attacked Clearway Group and has published the disclosure with a 'data_published' status, indicating exfiltration of company data. The leak post itself was non-descriptive (a redirect queue page), so the specific nature and volume of exfiltrated data cannot be confirmed from the post content alone.
Data the group says was taken
AI dossier — extracted from the leak post- Unspecified exfiltrated company data
Original description
AI-summarised, not from the leak postN/A
The leak post
captured from the group's siteYou have been placed in a queue, awaiting forwarding to the platform. Please do not refresh the page, you will be automatically redirected.
Sources
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

