DG2 Design Listed by anubis Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
DG2 Design has been listed by the anubis ransomware group, with internal files reported as exfiltrated in an attack disclosed on 1 April 2025. Individuals connected to the organisation should check whether their data is affected and take appropriate protective steps.
Ransomware groups continue to target professional services firms that hold sensitive client materials, using data theft and public leak-site listings as leverage. In this environment, even smaller design practices can appear on threat-actor sites, raising questions for clients and partners whose projects may be referenced in the claimed material.
On 1 April 2025, the ransomware group known as anubis listed DG2 Design on its leak site, asserting that internal files had been exfiltrated. Public reporting summarises the claimed material as including blueprints of M1 Bank, Mastercard and similar entities. The number of people affected remains unknown, and independent confirmation of the full scope has not been published.
Breaking down the breach
According to the available record, DG2 Design was listed by the anubis ransomware group on 1 April 2025. The group claims that internal files were taken in a ransomware attack. The reported summary of the material points to blueprints associated with M1 Bank, Mastercard and comparable organisations. No public figure has been given for the volume of data, the precise date of intrusion, or the technical method used. Whether any ransom demand was made or paid is undisclosed. The listing itself constitutes a claim by the group rather than a verified forensic finding released by the organisation or independent investigators.
Who is anubis?
Anubis is a ransomware operation that has appeared in public reporting as a double-extortion actor: it encrypts systems while also claiming to steal data and threatening to publish it on a dedicated leak site if payment is not received. Like other groups in this category, anubis typically posts victim names, sample files or descriptions of stolen material to increase pressure. Its listings are self-reported claims; they do not automatically prove that every file described was obtained or that the victim’s systems remain compromised. Prior public activity attributed to anubis has followed the same pattern of naming organisations across multiple sectors and asserting that internal documents were exfiltrated. No additional statements by anubis specifically about DG2 Design beyond the listing and the summarised content have been recorded in the facts available here.
DG2 Design and its sector
DG2 Design operates as a design practice. Firms of this type routinely produce architectural, engineering or interior drawings, technical specifications and project documentation for commercial clients, including financial institutions. Such work product often contains detailed floor plans, security-related layouts, infrastructure notes and client-specific requirements. Because these documents can reveal physical or operational details of client premises, a breach involving a design firm carries consequences that extend beyond the firm itself to the organisations whose projects appear in the files. Public detail on DG2 Design’s exact size, client list or security posture is limited; the significance of the incident therefore rests on the nature of the claimed material rather than on any confirmed organisational failure.
The information in question
The facts state that internal files were exfiltrated in a ransomware attack and that the reported summary includes blueprints of M1 Bank, Mastercard and similar entities. No exhaustive inventory of file types, volumes or additional data categories has been released. Design firms typically hold CAD drawings, PDF plan sets, correspondence, contracts and sometimes personal contact details of project stakeholders. Whether any of those broader categories were present in the claimed package remains unconfirmed. The exact contents of the alleged exfiltration are therefore known only through the group’s listing and the brief public summary; independent verification has not been published.
Why it matters
If the claimed blueprints are authentic and complete, they could expose physical layouts, access points or infrastructure details of the named financial institutions. That information, even if partial, may assist physical reconnaissance or social-engineering attempts against those organisations. For individuals whose names or contact details appear in project files, the risk is more ordinary: phishing, targeted fraud or unwanted contact that uses the leaked context to appear legitimate. For DG2 Design itself, the listing creates reputational and contractual pressure, potential regulatory scrutiny depending on jurisdiction, and the operational cost of investigation and remediation. Because the number of affected people is unknown and the full data set is unconfirmed, the precise scale of personal harm cannot yet be measured. The incident nonetheless illustrates how design practices sit at the intersection of intellectual property and client operational security.
Were you affected?
If you have worked with DG2 Design or appear in project documentation related to the named institutions, treat the listing as a prompt for caution rather than proof of personal exposure. Practical first steps include:
- Monitor financial and email accounts for unexpected activity or highly targeted messages that reference specific projects.
- Enable multi-factor authentication on important accounts and review recent login history.
- Be sceptical of unsolicited requests for information that cite blueprints, bank projects or design work.
- Request confirmation directly from DG2 Design or the relevant client organisation if you believe your data may be involved; do not rely solely on third-party claims.
Readers can also run a free exposure scan of their email address to check whether that address has already appeared in other known breach data sets. Public detail on this particular incident remains limited; further official statements from the organisation or law-enforcement sources would be required to refine the picture.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
KTR Real Estate Advisors Listed by anubis Ransomware GroupMarnell Financial Services Listed by anubis Ransomware GroupL. S. King and Associates Listed by anubis Ransomware GroupAndal Law Group Listed by anubis Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the DG2 Design Listed by anubis Ransomware Group →
Publicly posted by anubis — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.