Ransomware victim disclosure
← All victimsCOBU Architecture Studio
listed as COBU-ARCH.COM · Claimed by Clop · listed 4 months ago
Status timeline
- ListedFeb 7, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileCOBU Architecture Studio is an architecture firm founded in 2018 and based in Hoffman Estates, Illinois. The firm provides architecture, entitlement, and land planning services across multiple states, with a focus on socially meaningful projects. Their partners are NCARB certified and they offer supplemental services including structural, mechanical, electrical, and interior design through a network of consultants.
- Industry
- Architecture & Land Planning Services
- Address
- Hoffman Estates, IL, USA
- Founded
- 2018
Attack summary
Severity: medium — Data is marked as published by Clop, a group known for large-scale exfiltration, but the leak post provides no specific proof files, data inventory, or confirmation of regulated data exposure. The firm likely holds client project data and business records; without further evidence of PII or regulated data at scale, medium is appropriate.Clop claims to have compromised COBU Architecture Studio and has disclosed the data (status: data_published); however, the leak post content is uninformative (a redirect queue message), and no specific details on encryption, exfiltration volume, or data types are provided in the post.
Original description
AI-summarised, not from the leak postN/A
The leak post
captured from the group's siteYou have been placed in a queue, awaiting forwarding to the platform. Please do not refresh the page, you will be automatically redirected.
Sources
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

