Ransomware victim disclosure
← All victimsMontalba Architects
listed as MONTALBAARCHITECTS.COM · Claimed by Clop · listed 5 months ago
Status timeline
- ListedJan 25, 2026
- Data leakeddate unknown
At a glance
- Group
- Clop
- Status
- Data leaked
- Country
- United States
- Sector
- Construction
- Listed on leak site
- Jan 25, 2026
About the victim
AI dossier — public-source company profileMontalba Architects is an international architecture practice headquartered in Santa Monica, California, with additional offices in New York and Lausanne, Switzerland. The firm works across residential, retail, commercial, hospitality, and urban project types, and was named AIA California Firm of the Year in 2026. Their portfolio spans projects in the United States and internationally.
- Industry
- Architecture & Design Services
- Address
- 2525 Michigan Ave., Bldg. T4, Santa Monica, CA 90404
- Founded
- 2003
Attack summary
Severity: medium — Data is marked as published by a prolific ransomware group (Clop), which typically involves exfiltration, but no proof files, data inventory, or specifics about the nature or volume of compromised data are visible in the post, warranting a medium rather than high rating.Clop claims to have compromised Montalba Architects and has listed them as a victim with data published status; however, the leaked post content is non-descriptive and provides no explicit detail on whether data was exfiltrated or encrypted, nor what specific data is at stake.
Original description
AI-summarised, not from the leak postMONTALBA ARCHITECTS, INC. is a Swiss and American-based architecture firm founded by David Montalba. With offices in Santa Monica, California and Lausanne, Switzerland, they handle both residential and commercial projects. Known for their attention to detail, spatial fluidity, and creative use of light, they have won numerous design awards. They also prioritize environmentally-friendly solutions.
The leak post
captured from the group's siteYou have been placed in a queue, awaiting forwarding to the platform. Please do not refresh the page, you will be automatically redirected.
Sources
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

