← Blog
Industry security11 min read

Architecture firms and ransomware: plans, models and client files stolen

CannonDesign, DES Architects, David M. Schwarz, FDC Interiors: how ransomware groups target architectural IP — and why encrypted-before-upload storage changes the outcome.

Try it in one click.

Three private surfaces. Same zero-knowledge architecture.

Architecture is an IP business protected like an office A practice holds drawings, 3D models, structural calculations, tender documents, client contracts and personal data on everyone who ever worked there. Most of it lives in a shared network drive or a cloud drive, plaintext, reachable by anyone who gets one valid account. Ransomware groups worked this out years ago, and the sector has been hit repeatedly.

Documented cases

FirmYearGroupImpact
CannonDesign2023Avos Locker~5.7 TB exfiltrated — project drawings, employee data, IT infrastructure details. Part of it was later published.
DES Architects + Engineers2023–2024LockBitPersonal data (SSNs, passports, financial and medical information) of 1,144 people. Ransom demand around $380k.
David M. Schwarz Architects2025Minteye1.9 TB claimed.
FDC Interiors (UAE)2025MedusaInternal files, operational data and project material exposed.

Note what is being taken: not just money-adjacent data, but the project archive itself. Plans and models are the practice's only durable asset, and they are also perfectly saleable to a competitor or embarrassing to a client.

The wider pattern the sector shares - **Double extortion.** Encrypt on site, exfiltrate first. Paying restores files but never un-publishes them. - **Long dwell time.** Groups sit inside for weeks mapping the file server before triggering anything. - **Small IT teams, large data.** Practices of 50–500 people routinely hold multiple terabytes with one part-time IT provider. - **Consultant sprawl.** Engineers, contractors, visualisers and clients all get access to the same shared folders, often permanently.

Why this cannot play out the same way on DRIVUNO DRIVUNO encrypts every file **on your machine** before it is uploaded. The keys are derived from your credentials and never exist in readable form on our side.

  • Exfiltration returns ciphertext. A group that copies 5.7 TB from DRIVUNO copies 5.7 TB of unreadable data. There is no second copy in plaintext to steal, because we never held one.
  • No provider-side readability. No employee, support tool or legal order can produce a readable drawing. That is the architecture, not a policy.
  • Immutable backup defeats the encryption half of ransomware. Continuous encrypted mirroring keeps prior versions, and our own backups are immutable for a fixed retention window, so an attacker cannot overwrite or delete history.
  • Per-person keys instead of shared folders. Consultants and clients receive individually sealed access to a specific folder. Removing them rotates the keys of what they could reach — no more "the contractor from 2021 still has the drive".
  • External sharing expires. Public links live at most 24 hours, and what is needed to open them never reaches our servers.
  • Bulk download is detected and slowed. Every account gets an adaptive ceiling based on its own normal usage, so a large model export is fine while a whole-archive sweep triggers an alert and an automatic slowdown — the signal that would have surfaced a multi-terabyte exfiltration while it was still running.
  • No third-party analytics or trackers. One less vendor that can be breached on your behalf.

We do not publish thresholds or detection heuristics.

Practical takeaways for a practice 1. Assume the file server is the target, not the accounting system. 2. Keep an off-site copy that the attacker cannot delete, and verify you can restore it. 3. Stop permanent consultant access. Grant per project, revoke at handover. 4. Prefer storage where the provider is technically unable to read a drawing.

Encrypted project storage for architects DRIVUNO gives practices encrypted storage, per-project encrypted team folders, encrypted internal messaging and continuous encrypted backup of local project directories.

Try it in one click.

Three private surfaces. Same zero-knowledge architecture.

End-to-end encrypted