Ransomware victim disclosure
← All victimsClearway Group
listed as CLEARWAYGROUP.COM · Claimed by Cl0p · listed 5 months ago
Status timeline
- ListedJan 25, 2026
- Data leakeddate unknown
At a glance
- Group
- Cl0p
- Status
- Data leaked
- Country
- Hong Kong SAR China
- Listed on leak site
- Jan 25, 2026
About the victim
AI dossier — public-source company profileClearway Group is one of Canada's largest construction companies, headquartered in Maple, Ontario. Originally a sewer and watermain contractor, the company has expanded to offer a broad range of construction and utilities services through divisions including Clearway Utilities, Clearway Construction, and Sterling Haulage. The company serves clients across Canada with an emphasis on infrastructure and civil works.
- Industry
- Construction & Civil Engineering (Utilities, Sewer & Watermain)
- Address
- 45 Rodinea Road, Suite C, Maple, ON L6A 1R3, Canada
Attack summary
Severity: high — Data has been published by Cl0p, a prolific ransomware/extortion group known for large-scale exfiltration. Clearway Group is a major Canadian infrastructure/construction firm; exposure of project, financial, or personnel data from a company of this scale constitutes significant business data exfiltration.Cl0p claims to have attacked Clearway Group and the disclosure status is listed as data_published, indicating exfiltration and publication of company data. No specific ransom amount or data volume was stated in the leak post.
Data the group says was taken
AI dossier — extracted from the leak post- Corporate business data
- Internal company files
Original description
AI-summarised, not from the leak postN/A
Sources
- Victim siteCLEARWAYGROUP.COM
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

