CannonDesign, DES Architects, David M. Schwarz, FDC Interiors: how ransomware groups target architectural IP — and why encrypted-before-upload storage changes the outcome.
Three private surfaces. Same zero-knowledge architecture.
| Firm | Year | Group | Impact |
|---|---|---|---|
| CannonDesign | 2023 | Avos Locker | ~5.7 TB exfiltrated — project drawings, employee data, IT infrastructure details. Part of it was later published. |
| DES Architects + Engineers | 2023–2024 | LockBit | Personal data (SSNs, passports, financial and medical information) of 1,144 people. Ransom demand around $380k. |
| David M. Schwarz Architects | 2025 | Minteye | 1.9 TB claimed. |
| FDC Interiors (UAE) | 2025 | Medusa | Internal files, operational data and project material exposed. |
Note what is being taken: not just money-adjacent data, but the project archive itself. Plans and models are the practice's only durable asset, and they are also perfectly saleable to a competitor or embarrassing to a client.
We do not publish thresholds or detection heuristics.
Three private surfaces. Same zero-knowledge architecture.