Ransomware victim disclosure
← All victimsKLM Equities
listed as KLMEQUITIES.COM · Claimed by Clop · listed 4 months ago
Status timeline
- ListedFeb 7, 2026
- Data leakeddate unknown
At a glance
- Group
- Clop
- Status
- Data leaked
- Country
- United States
- Sector
- Financial Services
- Listed on leak site
- Feb 7, 2026
About the victim
AI dossier — public-source company profileKLM Equities is a commercial real estate investment and property management firm headquartered at 920 Broadway in the Flatiron District of New York City. The company owns and manages a portfolio of notable properties across major U.S. markets including New York, Los Angeles, Seattle, and Chicago. Featured holdings include landmark locations such as the TCL Chinese Theatre in Hollywood and 1415 Third Street Promenade in Santa Monica.
- Industry
- Commercial Real Estate Investment & Property Management
- Address
- 920 Broadway, New York, NY 10010
Attack summary
Severity: high — Clop is a well-documented ransomware group known for mass exfiltration; the disclosed status is 'data_published' indicating data was actually released. A real estate investment firm handling property transactions, financial data, and tenant/client PII across multiple major markets represents significant business and potentially regulated data exposure, warranting a high severity rating absent more granular detail.Clop claims to have compromised KLM Equities and has disclosed the attack with a 'data_published' status, suggesting exfiltration and publication of data. The leak post itself is uninformative (a queue/redirect placeholder), so specific details on data types or volume are not confirmed from the post.
Data the group says was taken
AI dossier — extracted from the leak post- Corporate financial records
- Property transaction documents
- Employee or executive personal information
- Client and tenant records
- Internal business communications
Original description
AI-summarised, not from the leak postN/A
The leak post
captured from the group's siteYou have been placed in a queue, awaiting forwarding to the platform. Please do not refresh the page, you will be automatically redirected.
Sources
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

