Ransomware victim disclosure
← All victimsSpohn Associates
listed as SPOHNASSOCIATES.COM · Claimed by Clop · listed 4 months ago
Status timeline
- ListedFeb 14, 2026
- Data leakeddate unknown
At a glance
- Group
- Clop
- Status
- Data leaked
- Country
- United States
- Sector
- Technology
- Listed on leak site
- Feb 14, 2026
About the victim
AI dossier — public-source company profileSpohn Associates is an architectural installation company based in Indiana (phone: 317-921-0021) that provides full project management and installation services for building products including ornamental metal, railing systems, skylights, curtain walls, and solar control systems. The company represents over 30 manufacturers and serves clients across Indiana, Kentucky, and Ohio.
- Industry
- Architectural Installation & Metal Fabrication
Attack summary
Severity: low — Post contains only a placeholder redirect message with no proof of breach, no data samples, no operational disruption claims, and no details of what was allegedly compromised. Classified as listing/announcement only.The leak post contains only a generic queue/redirect message with no substantive claims about data exfiltration, encryption, or breach details. No evidence of actual attack activity or data compromise is presented.
Original description
AI-summarised, not from the leak postSpohn Associates is a company that provides architectural specialities, offering design and construction solutions to architects, designers and contractors. Their products range from acoustics, signage, and sun control, to skatepark equipment and playground equipment. They also provide services like design assistance, project management, and installation. This US-based company collaborates with multiple manufacturers to provide the best solutions for their clients.
The leak post
captured from the group's siteYou have been placed in a queue, awaiting forwarding to the platform. Please do not refresh the page, you will be automatically redirected.
Sources
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

