Ransomware victim disclosure
← All victimsPeachtree Group
Claimed by Payoutsking · listed 2 months ago
Status timeline
- ListedApr 30, 2026
- Data leakeddate unknown
At a glance
- Group
- Payoutsking
- Status
- Data leaked
- Country
- United States
- Listed on leak site
- Apr 30, 2026
About the victim
AI dossier — public-source company profilePeachtree Group is a US-based real estate investment and management firm headquartered in Atlanta, Georgia. The company operates across credit, acquisitions, development, and hotel management, managing $15.8 billion in real estate asset value and 111 hotels with 13,852 keys. It serves institutional and private investors across the United States hospitality and commercial real estate sectors.
- Industry
- Real Estate Investment & Management; Hospitality
- Address
- Atlanta, Georgia, US
Attack summary
Severity: medium — Data has been published by the threat actor (disclosed_status = data_published), indicating confirmed exfiltration. However, no specific data inventory, proof count, or details about sensitive data categories are disclosed in the leak post. The company manages significant real estate and investor data, but the actual scope of exposure is unclear.The ransomware operator claims to have attacked Peachtree Group and published data, though no specific details about the nature of the breach (encryption, exfiltration, or both) or affected data types are provided in the post.
Original description
AI-summarised, not from the leak postPeachtree Group is a US-based hospitality-focused investment and management firm headquartered in Atlanta, Georgia. The company operates across real estate private equity, credit, and hotel management, specializing in acquiring, developing, and managing hotel properties. It serves institutional and private investors and is active across the United States hospitality and commercial real estate sectors.
Sources
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

