Ransomware victim disclosure
← All victimsNELSON Worldwide
listed as nelsonworldwide.com · Claimed by chaos · listed 3 months ago
Status timeline
- Listed
Mar 6, 2026
- Data leaked
At a glance
- Group
- chaos
- Status
- Data leaked
- Country
- United States
- Sector
- Business Services
- Listed on leak site
- Mar 6, 2026
About the victim
AI dossier — public-source company profileNELSON Worldwide is a US-based award-winning firm offering architecture, interior design, graphic design, environmental branding, and brand strategy services. The firm serves clients across sectors including healthcare, hospitality, retail, workplace, civic, and industrial markets. It operates across multiple US locations and has delivered projects for clients such as Shake Shack, Broward Health, and Prologis.
- Industry
- Architecture, Interior Design & Brand Strategy
- Employees
- 501-1000
Attack summary
Severity: high — Data has been confirmed as published by the threat actor, indicating successful exfiltration of business data from a professional services firm that likely holds sensitive client project files, contracts, and proprietary design materials for high-profile clients including healthcare and government facilities.The Chaos ransomware group claims an attack on NELSON Worldwide and has published data ('data_published' status), though the leak post does not specify whether encryption, exfiltration, or both occurred, and no ransom amount or data size was stated.
Data the group says was taken
AI dossier — extracted from the leak post- Business documents
- Client project files
- Design and architectural assets
- Internal communications
What the group claims
NELSON Worldwide is an award-winning firm delivering architecture, interior design, graphic design, and brand strategy services that transform all dimensions of the human experience, providing our clients with strategic and creative solutions that positively impact their lives and the environments w…
Sources
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
