CannonDesign notified 13,000 people of 2023 AvosLocker ransomware breach

Organization
CannonDesign
Exploit
Ransomware
Industry
Architecture and Engineering

CannonDesign, a United States architecture and engineering firm, began sending breach notification letters in August 2024 about an intrusion that had taken place more than 18 months earlier. The firm said an unauthorized party had access to its network between January 19 and January 25, 2023.

Comparitech reported that 13,049 people were notified starting August 19, 2024. The exposed information included names, addresses, Social Security numbers and driver's license numbers. Accounts differed on who received the letters: some reporting described them as current and former employees, while other coverage characterized the recipients as clients.

The AvosLocker ransomware group claimed the attack on February 2, 2023 and said it had taken 5.7 terabytes of data. After extortion attempts failed, roughly two terabytes were published in September 2023 on Dunghill Leaks, a site operated by the Dark Angels group. That set was said to include project files, hiring records, client information, marketing material and IT infrastructure details. CannonDesign has not verified either group's claims about the volume or contents of the stolen data.

The firm completed its investigation on May 3, 2024 but did not publicly explain the further delay before individuals were notified. CannonDesign said it was unaware of any attempted misuse of the information and offered 24 months of credit monitoring through Experian, with an enrollment deadline of November 29, 2024.

Sources