Delap & Waller Listed by lynx Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Delap & Waller was listed by the lynx ransomware group on December 04, 2024, after internal files were taken in a ransomware attack. Anyone connected with the firm should check whether their information was involved and follow any guidance the company issues.
When a professional services firm appears on a ransomware group's leak site, the immediate concern for clients, staff and project partners is whether personal or commercial information has left the organisation's control. In the case of Delap & Waller, the listing raises practical questions about who may be affected and what steps those people should take while fuller details remain limited.
Public reporting on 4 December 2024 stated that the engineering consultancy had been named by the lynx ransomware group. The group claims to have taken more than 300 GB of material from the firm's network. The number of people whose information may be involved is unknown, and independent confirmation of the full scope has not been published.
Inside the incident
According to the available record, Delap & Waller was listed by the lynx ransomware group on or around 4 December 2024. The group's own statement asserts that it exfiltrated internal files during a ransomware attack and that it holds more than 300 GB of data taken from the network. No further technical detail—such as the precise date of initial access, the method of entry, or whether encryption was also deployed—has been disclosed in the public summary. The number of individuals potentially affected remains unknown. Because the information originates from the threat actor's leak-site claim, it should be treated as an unverified assertion until corroborated by the organisation or independent investigators.
The group behind it: lynx
Lynx is a ransomware operation that became active in public view during 2024. Like many contemporary groups, it follows a double-extortion model: data is copied from the victim network before encryption is applied, and the group then threatens to publish the stolen material if a ransom is not paid. Victims are typically listed on a dedicated leak site, sometimes accompanied by sample files or volume claims intended to pressure the organisation. Lynx has been observed targeting a range of mid-sized enterprises across different sectors, often relying on common initial-access techniques such as compromised credentials or unpatched remote-access services. Public reporting has not established any unique technical signature that would distinguish this particular claim against Delap & Waller from the group's broader pattern of activity. The listing itself remains a claim made by the group rather than a confirmed forensic finding.
About Delap & Waller
Delap & Waller is a multi-disciplinary engineering consultancy focused on building services—mechanical, electrical, plumbing and related design work—for construction and infrastructure projects. Firms of this type routinely handle project drawings, specifications, client correspondence, supplier contracts, employee records and, in some cases, personal data belonging to building occupants or end users. Because the work sits at the intersection of design, construction and facilities management, the organisation's systems often contain both commercially sensitive intellectual property and personal information about staff and third parties. A breach at such a firm therefore carries consequences that extend beyond the company itself to clients, contractors and individuals whose details appear in project files.
What data was at risk
The only description provided is that internal files were allegedly exfiltrated in a ransomware attack and that the group claims to hold more than 300 GB of material taken from the network. No itemised list of data categories—such as names, contact details, financial records or project documents—has been published. Organisations in the building-services sector typically store employee personnel files, client contact information, contractual documents, design drawings and correspondence. Whether any of those categories were among the files taken remains unconfirmed. Until a fuller disclosure is made, the precise contents of the claimed 300-plus-gigabyte archive cannot be verified.
Why it matters
For individuals whose information may have been present, the practical risks include targeted phishing, identity fraud or unwanted contact that exploits knowledge of employment, project involvement or personal details. For the firm and its clients, the exposure of design files or contractual material can create commercial disadvantage, contractual disputes or regulatory notification duties under data-protection law. Because the volume claimed is substantial and the number of affected people is unknown, the uncertainty itself becomes a source of ongoing risk: people cannot easily determine whether they need to take protective steps. The incident also illustrates the broader pattern in which professional-services firms, holding concentrated collections of third-party data, become attractive targets for ransomware groups seeking leverage.
If your data was in this claimed breach
If you have a past or present connection with Delap & Waller—as an employee, client, contractor or project participant—treat the possibility of exposure seriously even while details remain incomplete. Monitor financial and email accounts for unusual activity, enable multi-factor authentication wherever it is available, and be cautious of unsolicited messages that reference projects or personal details that could have come from internal files. Consider placing fraud alerts with relevant credit-reference agencies if you believe sensitive personal data may have been involved. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets; such a check provides an additional, independent signal while official notifications are still pending.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Interoute agency Listed by lynx Ransomware Groupplowmancraven.co.uk Listed by lynx Ransomware GroupPlowman Craven Listed by lynx Ransomware GroupPBS group Listed by lynx Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Delap & Waller Listed by lynx Ransomware Group →
Publicly posted by lynx — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.