ehdd.com Listed by incransom Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
ehdd.com was listed by the incransom ransomware group on February 20, 2025, after internal files were exfiltrated in a ransomware attack. An undisclosed number of individuals may have been affected; check the group’s post and any official statements to determine whether your data was involved and what steps to take.
People who have worked with, for, or alongside the architecture firm EHDD may now face uncertainty about whether their personal or professional information sits among files claimed to have been taken in a ransomware incident. Public reporting on 20 February 2025 shows that the group known as incransom listed ehdd.com on its leak site, asserting that internal files were exfiltrated. The number of individuals affected remains unknown, and exact contents of any stolen data have not been independently confirmed, yet the listing alone raises practical questions about privacy, identity risk, and professional exposure for anyone whose details the firm may hold.
Because EHDD designs public and private buildings used by large numbers of people, a compromise of its internal systems can touch more than employee records; it can involve project documentation, client correspondence, and operational material that, if misused, creates real-world consequences for those named in it.
Inside the incident
According to the available record, ehdd.com was listed by the incransom ransomware group on or around 20 February 2025. The group claims that internal files were exfiltrated as part of a ransomware attack. No public confirmation has established the precise date the intrusion began, the technical method used to gain access, the volume of data taken, or whether systems were encrypted in addition to the alleged theft. The number of people affected is listed as unknown. Beyond the leak-site claim itself, further operational detail has not been disclosed in the material provided.
Ransomware incidents of this type typically involve unauthorized access followed by data theft and a threat to publish or sell the material if a ransom is not paid. In this case, only the listing and the assertion of exfiltrated internal files have been reported; independent verification of the full scope remains limited.
The group behind it: incransom
Incransom is a ransomware operation that has appeared in public threat reporting as a group that practices double extortion: encrypting systems while also stealing data and threatening to leak it on a dedicated site. Like many such actors, it typically advertises victims on a dark-web leak site to pressure payment and to demonstrate capability. Public analyses of the group describe the use of standard ransomware tooling, initial access through common vectors such as compromised credentials or vulnerable remote services, and the subsequent publication of sample files or full archives when negotiations fail or stall.
The listing of ehdd.com is therefore a claim made by the group. No independent forensic confirmation of the volume, sensitivity, or authenticity of any posted material is contained in the facts available for this incident. Readers should treat assertions originating solely from a ransomware leak site as unverified until corroborated by the victim organization or by reputable third-party analysis.
ehdd.com and its sector
EHDD is an architecture firm founded in 1946 and headquartered in San Francisco. It designs built environments for aquariums, museums and science centers, educational institutions, corporate offices, mixed-use developments, and government clients, serving projects around the world. The firm has been recognized as a Top 10 AIA COTE honoree and has been featured in discussions of high-performance design practices. Architecture practices of this scale routinely maintain digital repositories of design drawings, specifications, contracts, client communications, employee records, and project-management data.
A breach affecting such a firm is consequential because the sector handles both commercially sensitive intellectual property and personally identifiable information belonging to staff, consultants, and clients. Public buildings and cultural institutions also generate documentation that can include security-related or operational details whose exposure could create secondary risks beyond simple privacy harm.
What data was at risk
The facts state that internal files were exfiltrated in a ransomware attack. No further breakdown of file types, record counts, or categories of personal data has been disclosed. Organizations of EHDD’s type commonly store employee personnel files, payroll and benefits data, client contact lists, contracts, architectural drawings, project correspondence, and financial records. Whether any of those categories were among the material claimed by incransom has not been confirmed publicly. Exact contents therefore remain unconfirmed, and no specific data elements should be treated as verified exposures at this stage.
What's at stake
For individuals, the principal risks are identity theft, targeted phishing, and misuse of professional or personal details if those details were present in the taken files. Even limited internal documents can contain names, email addresses, phone numbers, or project roles that enable social-engineering attacks. For the firm itself, consequences can include regulatory notification duties, contractual obligations to clients, reputational damage, and the operational cost of investigation and remediation. Because the scale of the alleged exfiltration is unknown, the breadth of these risks cannot yet be quantified; the uncertainty itself is part of the practical burden placed on anyone who may be affected.
What to do if you're exposed
If you have a past or present relationship with EHDD—as an employee, contractor, client, or project partner—monitor financial and email accounts for unusual activity and treat unexpected messages that reference the firm with caution. Consider placing fraud alerts with major credit bureaus if you believe sensitive personal data may have been involved, and change passwords on any accounts that reused credentials potentially stored by the organization. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets; such a check provides one concrete data point while official notifications, if any, are still pending.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
OSI Systems, Inc. Listed by incransom Ransomware Groupdeerfield.com (singulargenomics.com) Listed by incransom Ransomware Groupwww.modcomedia.com Listed by incransom Ransomware Groupwww.integer.net Listed by incransom Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the ehdd.com Listed by incransom Ransomware Group →
Publicly posted by incransom — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.