Cordogan Clark and Associates (cordoganclark.com) Listed by fog Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Cordogan Clark and Associates (cordoganclark.com) was listed by the fog ransomware group on October 16, 2024, after internal files were exfiltrated in a ransomware attack. The number of individuals affected is not disclosed; anyone connected to the firm should review their accounts and monitor for suspicious activity.
On October 16, 2024, Cordogan Clark and Associates, the firm operating at cordoganclark.com, was listed by the fog ransomware group. Public reporting indicates the group claims to have exfiltrated 107 GB of internal files in a ransomware attack. The number of people affected remains unknown, and further operational details have not been disclosed. For an architecture and design practice that routinely handles project documentation, client materials, and internal records, any confirmed exposure of internal files carries practical consequences for the organisation and those whose information may appear in its systems.
What is known so far rests on the group's leak-site listing and the limited summary attached to it. No independent confirmation of the full scope, exact timing of intrusion, or precise contents has been made public. The incident therefore stands as an unverified claim of data theft paired with a ransomware event, pending any further statements from the firm or investigators.
Inside the incident
Public detail on the incident itself is limited to the October 16, 2024 listing. The fog group claims that 107 GB of internal files were exfiltrated during a ransomware attack against Cordogan Clark and Associates. No official figure has been released for the number of individuals whose data may be involved; that count is recorded as unknown. The precise method of initial access, the duration of any network presence, the encryption status of systems, and whether a ransom demand was issued or paid have not been disclosed in available reporting.
Ransomware incidents of this type typically involve both encryption of systems and theft of data for leverage, yet nothing beyond the claimed volume of internal files and the fact of the listing has been confirmed for this case. Organisations in the design and construction sector often discover such events only after threat actors post claims on dedicated leak sites. Until Cordogan Clark and Associates or law-enforcement sources provide additional verified information, the scale and technical particulars remain unconfirmed beyond the 107 GB figure attached to the listing.
The group behind it: fog
Fog is a ransomware operation that has appeared in public reporting as a group that conducts double-extortion attacks: encrypting victim systems while simultaneously stealing data and threatening to publish it if payment is not made. Like other contemporary ransomware actors, fog typically advertises victims on a dedicated leak site, posting sample files or volume claims to increase pressure. The group has been observed targeting a range of sectors, including professional services, and has used common initial-access vectors such as compromised credentials, phishing, or exploitation of unpatched remote-access services—tactics documented across multiple prior incidents involving the same brand.
In this instance the group claims Cordogan Clark and Associates as a victim and asserts that 107 GB of internal files were taken. That assertion originates solely from the leak-site listing; it has not been independently verified in the available facts. Fog's public pattern is to escalate pressure by releasing additional samples or full archives if negotiations stall, yet no further releases specific to this organisation have been detailed in the reporting used here. Attribution therefore rests on the group's own claim rather than on forensic confirmation released by the victim or third-party investigators.
Who is Cordogan Clark and Associates (cordoganclark.com)?
Cordogan Clark and Associates is an architecture, engineering and design firm that operates under the domain cordoganclark.com. Firms of this type provide professional services for building design, planning, and related project delivery. They routinely maintain digital repositories of architectural drawings, specifications, client correspondence, contracts, financial records, employee personnel files, and project-management data. Because these materials often include both proprietary design work and personally identifiable information belonging to staff, clients, and project partners, a breach of internal systems can affect multiple parties beyond the firm itself.
A ransomware incident at such an organisation is consequential for two reasons. First, the firm may face operational disruption if systems are encrypted or if project files become unavailable. Second, the nature of the data typically held means that any exfiltration can expose sensitive commercial information and personal details. Public knowledge of the sector does not, however, establish the exact contents of the 107 GB claimed in this case; that remains unconfirmed.
The information in question
The facts state only that internal files were exfiltrated in a ransomware attack and that the volume claimed is 107 GB. No further breakdown of file types, folders, or data categories has been disclosed. Organisations in architecture and professional design commonly store CAD and BIM models, client contracts, invoices, employee records, email archives, and internal memoranda. These repositories can contain names, addresses, contact details, financial account information, Social Security numbers or other government identifiers, and proprietary design intellectual property.
Because the precise contents of the claimed 107 GB have not been confirmed, it is not possible to state as fact which of these categories—if any—were included. The listing refers generically to internal files. Readers should therefore treat any assumption about specific personal or commercial data as unconfirmed until the firm or investigators release a verified inventory.
Why it matters
For individuals whose information may reside in the firm's systems, the primary risks are identity theft, targeted phishing, and financial fraud if personal identifiers or contact details were among the internal files. Even partial exposure of names, email addresses, or project affiliations can enable social-engineering attacks that appear legitimate because they reference real work. For the organisation, the consequences include potential regulatory notification obligations, contractual liabilities to clients, reputational damage, and the cost of forensic investigation, system restoration, and enhanced security controls.
Business partners and clients may also face secondary exposure if shared project files or correspondence were taken. The absence of a confirmed headcount of affected people means the full human impact cannot yet be quantified; the unknown figure itself underscores the need for caution rather than alarm. Concrete steps—monitoring credit, watching for unusual account activity, and treating unsolicited communications with heightened scrutiny—remain the practical response while details stay limited.
Were you affected?
If you have worked with, been employed by, or supplied services to Cordogan Clark and Associates, treat the possibility of exposure as real but unconfirmed. Begin by reviewing recent account statements and credit reports for unfamiliar activity. Enable multi-factor authentication on email and financial accounts, and be alert to phishing messages that reference architectural projects or the firm by name. Change passwords on any accounts that may have been reused or shared in professional correspondence.
You can also run a free exposure scan of your email address to check whether it has already appeared in known breach data sets. Such scans draw on publicly documented leaks and can provide an early indication that further monitoring is warranted. If you receive formal notification from the firm, follow the specific guidance it provides, including any offers of credit monitoring. Until more verified information is released, these measured steps remain the most useful course of action.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Forum Architecture & Interior Design (forumarchitecture.com) Listed by fog Ransomware GroupPlanters Telephone Cooperative (planters.net) Listed by fog Ransomware GroupComplete Recycling Services (completerecyclingservices.com) Listed by fog Ransomware GroupSCOLARO FETTER GRIZANTI & McGOUGH, P.C. (scolaro.com) Listed by fog Ransomware GroupLatest breaches
Publicly posted by fog — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.