Incident

CannonDesign reports ransomware attack, data breach


Learn More

CannonDesign, an architectural, engineering, and consulting firm based in New Yortk City, has confirmed a data breach linked to the Avos Locker ransomware attack. The breach occurred between January 19-25, 2023, involved unauthorized access to CannonDesign’s network, resulting in the theft of sensitive data. The firm detected the breach on January 25, 2023, but only completed its investigation on May 3, 2024.

Although CannonDesign did not explicitly name the threat actors in its notifications, it was confirmed that the Avos Locker ransomware group was responsible. On February 2, 2023, Avos Locker claimed responsibility for the attack, alleging they had exfiltrated 5.7 TB of data, including corporate files, project schematics, and client information.

After CannonDesign refused to meet the ransom demands, the data was leaked online, first by Dunghill Leaks in September 2023 and later on hacker forums such as ClubHydra and Breached Forums.

The stolen data includes:

  • Names
  • Addresses
  • Social Security Numbers (SSNs)
  • Driver’s license numbers

The number of affected individuals is not disclosed.

Notification letters are sent to impacted individuals more than a year after the incident and three months after the completion of the investigation, with no explanation for the delay. CannonDesign is offering 24 months of credit monitoring through Experian to those affected, which may be useless this late after the initial breach.

CannonDesign reports ransomware attack, data breach