Ransomware victim disclosure
← All victimsWEDGE Group
listed as WEDGE · Claimed by Akira · listed 3 months ago
Status timeline
- ListedMar 9, 2026
- Data leakeddate unknown
At a glance
- Group
- Akira
- Status
- Data leaked
- Country
- United States
- Listed on leak site
- Mar 9, 2026
- Data size
- 15 GB
About the victim
AI dossier — public-source company profileWEDGE Group is a Houston, Texas-based firm specializing in private investments and the management of commercial real estate properties. The company offers office spaces across multiple Texas markets including Houston, Sugar Land, Austin, Irving, and McKinney.
- Industry
- Private Equity & Commercial Real Estate Investment
- Address
- Houston, Texas, United States
Attack summary
Severity: critical — Confirmed exfiltration of regulated PII at scale including SSNs, passports, and government tax/employment forms (W-9, I-9), combined with sensitive financial and client data from a private investment firm; disclosure status is data_published.Akira claims to have exfiltrated approximately 15 GB of corporate data, including employee identity documents (passports, driver's licenses, SSNs), tax forms (W-9, I-9), financial records, investment project files, client information, and NDAs; data publication is described as imminent.
Data the group says was taken
AI dossier — extracted from the leak post- Employee passports
- Driver's licenses
- Social Security Numbers (SSNs)
- W-9 tax forms
- I-9 employment eligibility forms
- Financial records
- Investment project files
- Client information
- Non-disclosure agreements (NDAs)
What the group claims
WEDGE Group specializes in private investments and the management of commercial real estate properties. They offer a range of offi ce spaces in various locations, including Houston, Sugar Land, Au stin, Irving, and McKinney. We will upload 15gb of corporate data soon. Employee passports, D Ls, SSNs, w9, I9 forms. Lots of financial information, investment projects, client information, NDAs, etc.
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

