Ransomware victim disclosure
← All victimsWardhaven Capital Limited
listed as WARDHAVENCAPITAL.COM · Claimed by Clop · listed 4 months ago
Status timeline
- ListedFeb 7, 2026
- Data leakeddate unknown
At a glance
- Group
- Clop
- Status
- Data leaked
- Sector
- Financial Services
- Listed on leak site
- Feb 7, 2026
About the victim
AI dossier — public-source company profileWardhaven Capital Limited is a boutique asset management firm headquartered in Wan Chai, Hong Kong, with a representative office in Ho Chi Minh City, Vietnam. The firm is an active investor in Vietnamese listed equities. It operates as a registered investment manager offering funds and portfolio management services.
- Industry
- Boutique Asset Management
- Address
- Room 10, 29/F, Dah Sing Financial Centre, 248 Queen's Road East, Wan Chai, Hong Kong
Attack summary
Severity: high — Clop is a well-known exfiltration-focused ransomware group and the status is data_published, meaning data has been released. As a financial services firm handling investor and fund data, exposure likely involves sensitive financial and potentially regulated PII, warranting a high severity rating despite limited proof details in the post.Clop claims to have compromised Wardhaven Capital Limited and the disclosure status is marked as data_published, indicating exfiltration and potential publication of company data. The leak post itself provides no readable detail on specific data types or volume due to a redirect/queue page.
Data the group says was taken
AI dossier — extracted from the leak post- Financial records
- Investor data
- Portfolio/fund information
- Internal business documents
Original description
AI-summarised, not from the leak postN/A
The leak post
captured from the group's siteYou have been placed in a queue, awaiting forwarding to the platform. Please do not refresh the page, you will be automatically redirected.
Sources
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

