Ransomware victim disclosure
← All victimsWheelock Street Capital
listed as WHEELOCKST.COM · Claimed by Clop · listed 4 months ago
Status timeline
- ListedFeb 7, 2026
- Data leakeddate unknown
At a glance
- Group
- Clop
- Status
- Data leaked
- Country
- United States
- Listed on leak site
- Feb 7, 2026
About the victim
AI dossier — public-source company profileWheelock Street Capital L.L.C. is a private real estate investment firm founded in 2008 by Merrick R. Kleeman and Jonathan H. Paul, headquartered in Greenwich, CT with an additional office in Boston, MA. The firm employs a vertically integrated, hybrid investment model across major real estate asset classes including hospitality, industrial, residential, land, and retail/mixed-use. It manages significant institutional capital with billions in total asset value acquired.
- Industry
- Private Real Estate Investment & Equity
- Address
- 660 Steamboat Road, 3rd Floor, Greenwich, CT 06830
- Founded
- 2008
Attack summary
Severity: high — Wheelock Street Capital manages significant institutional investor capital and sensitive financial/real estate transaction data. Clop has a confirmed pattern of exfiltrating and publishing data; the disclosed status is 'data_published', indicating actual data release. Exposure of investor records, financial data, and proprietary deal-flow information constitutes significant business and potentially regulated financial data exposure.Clop claims to have attacked Wheelock Street Capital and has published data (disclosed status: data_published); the leak post itself provides no additional detail on whether encryption or exfiltration occurred, but the published status indicates data has been released or is being released.
Data the group says was taken
AI dossier — extracted from the leak post- Investor financial records
- Real estate transaction documents
- Institutional investor data
- Internal business communications
- Portfolio and deal-flow data
Original description
AI-summarised, not from the leak postN/A
The leak post
captured from the group's siteYou have been placed in a queue, awaiting forwarding to the platform. Please do not refresh the page, you will be automatically redirected.
Sources
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

