Ransomware victim disclosure
← All victimsKnit
Claimed by Akira · listed 11 hours ago
Status timeline
- ListedSep 28, 2026
- Data leakeddate unknown
At a glance
- Group
- Akira
- Status
- Data leaked
- Sector
- Technology
- Listed on leak site
- Sep 28, 2026
About the victim
AI dossier — public-source company profileKnit is an architecture firm focused on urban design and community improvement projects. The company works with clients on city planning, commercial, educational, and residential development initiatives.
- Industry
- Architecture & Design
Attack summary
Severity: critical — Confirmed exfiltration of large-scale sensitive PII (passports, driver's licenses, credit card data) combined with regulated business data (client information, financial records, NDAs). The 175 GB volume and diversity of personal/financial data elevates this to critical severity.The Akira group claims to have exfiltrated 175 GB of corporate data including employee personal information (passports, driver's licenses, credit cards), project details, financial records, client information, and confidential agreements.
Data the group says was taken
AI dossier — extracted from the leak post- Employee passports
- Employee driver's licenses
- Employee credit card information
- Project files
- Financial records
- Client information
- NDAs and contracts
What the group claims
One of our essential beliefs is that architecture changes lives. This belief guides our path ev ery day. We seek clients and relationships who are equally interested in improving their city, their business, their school, their neighborhood or the place they call home. We will upload 175gb of corporate data soon. Employee information (passports, DLs, credit cards ), projects, financials, client information, NDAs and so on.
Source
Indexed 11 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

