Ransomware victim disclosure
← All victimsPosen Architects
Claimed by Abyss · listed 3 days ago
Status timeline
- Listed
May 18, 2026
Current state: Listed for ransom
At a glance
- Group
- Abyss
- Status
- Listed for ransom
- Sector
- Architecture
- Listed on leak site
- May 18, 2026
- Data size
- 29 GB
- Ransom demanded
- $50
About the victim
AI dossier — public-source company profilePosen Architects is an architecture firm. Based on the victim name and sector classification, the firm likely provides architectural design and planning services. No public site content was available to confirm further details about their location, scale, or specific specialisations.
- Industry
- Architecture & Design
Attack summary
Severity: high — 724 GB of uncompressed data is a substantial exfiltration from an architecture firm, likely containing proprietary project designs, client contracts, and potentially sensitive building/infrastructure data; the group claims data is already publicly released.The Abyss ransomware group claims to have exfiltrated 724 GB of uncompressed data from Posen Architects and states the data is now freely published. No details about encryption are mentioned in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Architectural project files
- Business documents
- Potentially client records
What the group claims
Mentioned alongside Promise Technology, Inc. in the leak listing.
The leak post
captured from the group's siteWe publish the data that is now freely available! ##### In the depths of software development. Unlocking the secrets of Promise Technology, Inc. Today we publish the first part from a major leak at Promise Technology, Inc. Contact for communication. TOX: 01D33073173C72E543DDCD6895EAE05A57CFDF7B7D906FB99FCD0F26C335290050EA900F8FDA Posen Architects 724Gb uncompressed data
Screenshot of the leak post

Sources
Source
Indexed 3 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
