Ransomware victim disclosure
← All victimsFFKR Architects
Claimed by Incransom · listed 5 hours ago
Status timeline
- ListedAug 24, 2026
- Data leakeddate unknown
At a glance
- Group
- Incransom
- Status
- Data leaked
- Country
- United States
- Sector
- Professional Services
- Listed on leak site
- Aug 24, 2026
About the victim
AI dossier — public-source company profileFFKR Architects is an architecture and interior design firm headquartered in Utah with offices in Arizona and Idaho. The firm employs over 170 professionals and provides architecture, landscape architecture, interior design, and environmental graphic design services across healthcare, education, hospitality, and commercial sectors.
- Industry
- Architecture & Interior Design
- Address
- Utah, US (primary); additional offices in Arizona and Idaho
- Employees
- 170+
Attack summary
Severity: medium — Data has been published (disclosed status confirms 'data_published'), but the leak post provides no details about data type, scope, or sensitivity. No proof files or screenshots are advertised. The victim is a professional services firm with no stated exfiltration of regulated data (PII, medical, financial, etc.).The incransom group claims to have compromised FFKR Architects and published data. The leak post does not specify whether data was encrypted, exfiltrated, or both, nor does it detail what specific data categories were accessed or compromised.
What the group claims
FFKR Architects is a leading architecture and interior design firm based in Utah, with additional offices in Arizona and Idaho. They offer a wide range of services including architecture, landscape architecture, interior design, and environmental graphic design. The firm is known for its design excellence and commitment to environmental leadership, serving various sectors such as healthcare, education, hospitality, and commercial projects. With a team of over 170 professionals, FFKR empowers clients through innovative visualization techniques, ensuring informed decision-making.
Sources
Source
Indexed 5 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

