Erdy McHenry Architecture Listed by akira Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Erdy McHenry Architecture was listed by the Akira ransomware group on August 14, 2025, after internal files were exfiltrated in a ransomware attack. The number of people affected has not been disclosed; anyone connected to the firm should check their accounts for unusual activity and change passwords if they suspect exposure.
Ransomware groups continue to target professional services firms, including architecture practices, as part of a broader pattern of double-extortion attacks that combine system encryption with data theft. In this environment, even mid-sized design firms have become visible targets because their networks often hold financial records, project files, and personal information belonging to staff and clients.
On August 14, 2025, the ransomware group known as akira listed Erdy McHenry Architecture on its leak site, claiming to have exfiltrated internal files. The number of people affected remains unknown, and independent confirmation of the full scope is limited. The listing itself is a claim by the group rather than a verified disclosure by the firm.
Breaking down the breach
Public reporting states that Erdy McHenry Architecture was listed by the akira ransomware group on August 14, 2025. According to the group’s own statement on its leak site, more than 26 GB of files were taken. The group described the material as essential corporate documents that include financial data such as payment details and invoices, employee information, a limited volume of personal files, and customer data. No further technical details about the intrusion method, the exact date of compromise, or whether systems were encrypted have been made public. The number of individuals whose information may be involved is listed as unknown. All specifics about volume and content originate from the group’s claim and have not been independently verified in available reporting.
Inside akira
Akira is a ransomware operation that became active in 2023 and has since conducted numerous double-extortion campaigns. The group typically gains initial access through compromised credentials or unpatched remote services, moves laterally inside the network, exfiltrates data, and then deploys ransomware. Victims are pressured both by the encryption of systems and by the threat of public release of stolen files on a dedicated leak site. Akira has previously targeted organizations across manufacturing, education, healthcare, and professional services. Its operators commonly publish sample file lists or screenshots to demonstrate possession of data and set deadlines for payment. In this case the group claims to hold more than 26 GB of Erdy McHenry Architecture material and states it is prepared to upload the files; that assertion remains an unverified claim by the actors.
About Erdy McHenry Architecture
Erdy McHenry Architecture is a firm that provides architectural design services across academic, cultural, agricultural infrastructure, commercial, housing, and health-science projects. Like most architecture practices, it maintains digital repositories of project drawings, contracts, financial records, employee personnel files, and client correspondence. These materials are essential to day-to-day operations and often contain both proprietary design information and personally identifiable data. A breach at such a firm can therefore affect not only the company itself but also its staff, clients, and project partners who rely on the confidentiality of shared documents.
What was likely exposed
The only concrete description of the data comes from akira’s leak-site claim, which states that more than 26 GB of internal files were exfiltrated. The group specifically names financial data (payment details and invoices), employee information, a limited amount of personal files, and customer data. Public reporting does not independently confirm the exact contents or the completeness of that list. Organizations of this type routinely hold payroll records, tax identifiers, bank details for vendors and clients, project contracts, and contact information for staff and customers. Whether any of those categories were present in the claimed 26 GB archive remains unconfirmed beyond the group’s assertion. No official inventory from Erdy McHenry Architecture has been released in the available facts.
Why it matters
If the claimed files are authentic, employees could face risks of identity theft or targeted phishing that uses accurate personal or payroll details. Clients and project partners might see invoices, payment information, or contractual terms appear in criminal hands, raising the possibility of fraud or competitive misuse of design and financial data. For the firm itself, the incident can disrupt ongoing projects, damage client trust, and create regulatory notification obligations depending on the jurisdictions involved. Because the number of affected individuals is unknown and the precise data types are not independently verified, the full scale of harm cannot yet be measured. Even so, the combination of financial and personal records typical of an architecture practice makes the potential exposure consequential for those whose information may be included.
Were you affected?
If you are a current or former employee, client, or vendor of Erdy McHenry Architecture, monitor financial accounts and credit reports for unusual activity and be alert to phishing messages that reference the firm or its projects. Consider placing a fraud alert with credit bureaus if you believe sensitive identifiers may have been involved. Readers can also run a free exposure scan of their email address to check whether their information has already appeared in known breach data sets. Official notifications, if any, will come directly from the firm or relevant authorities; until then, treat the akira listing as an unconfirmed claim and take standard protective steps.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Alliance Roofing Listed by akira Ransomware GroupRafael Construction Listed by akira Ransomware GroupFarwest Fabrication Listed by akira Ransomware GroupLatitude 33 Planning& Engineering Listed by akira Ransomware GroupLatest breaches
Publicly posted by akira — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.