Skip to content

Wallstreet

Ransomware Group1 claimLast activity:

Overview

Wallstreet is an emerging ransomware and data-extortion operation first tracked publicly in late June 2026. Ransomware.live dates the operation’s appearance to June 26. Public reporting does not establish the operators’ identities, location, code lineage, affiliate structure or relationship to an earlier group.

Activity and targeting

Red Piranha described Wallstreet as active during July 4-10 and listed alleged victims in government, health care, insurance and automotive services across several countries. The small public sample supports describing its activity as multisector, but it does not establish a fixed targeting strategy. Ransomware.live continued to index Wallstreet victim claims in August.

Methods and operational characteristics

Wallstreet operates a data-leak site used to name alleged victims and pressure them with threatened disclosure. Its Andover listing asserted several data categories and displayed a countdown before further information would be revealed. Public technical reporting has not established an encryptor, ransom-note format, malware family, access vector or Wallstreet-specific technical indicators beyond the leak-site infrastructure. Encryption and the authenticity of actor-claimed data therefore remain unconfirmed.

What type of group is it?

Wallstreet presents as a financially motivated ransomware and data-extortion operation. That classification is based on its leak-site model and public threat-intelligence tracking, not on verified malware analysis or confirmed victim reporting. Its operating structure, membership, technical capabilities and possible links to other actors remain unresolved.

Incident claim

Andover Town and Schools Cyberattack

Incident date: Source: ransomware.liveDiscovered:

Claim details

Wallstreet listed `Andover` and used a description identifying the Town of Andover, Massachusetts. The listing asserted possession of documents, databases, emails, personal data and media and displayed a countdown before a redacted confidential item would be revealed. The claim is unverified and does not establish access, theft, encryption, a ransom demand or responsibility for the Aug. 13 cyberattack.

Impacted organizations

Impacted location

Sources