Pryor Morrow Listed by dragonforce Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Pryor Morrow was listed by the dragonforce ransomware group on April 14, 2025, after internal files were exfiltrated in a ransomware attack. The number of individuals affected remains undisclosed; anyone connected to the organization should verify whether their data was involved and follow recommended security steps.
In an era when ransomware groups routinely target professional services firms that hold project files, client records and operational data, the listing of Pryor Morrow on a cyber-criminal leak site adds another entry to a growing list of architecture and engineering practices drawn into these incidents. Public reporting on 14 April 2025 states that the firm has been named by the dragonforce ransomware group, which claims to have exfiltrated internal files. The number of people affected remains unknown, and many operational details have not been disclosed.
For clients, staff and partners of a practice that designs schools, government buildings and recreational facilities, any unauthorised access to internal material raises practical questions about confidentiality, project integrity and personal data. This article sets out only what has been reported, places the claim in context, and outlines steps individuals can take if they believe their information may have been involved.
What happened
According to public reporting dated 14 April 2025, Pryor Morrow was listed by the dragonforce ransomware group. The group claims that internal files were exfiltrated in a ransomware attack. No further technical details—such as the initial access method, the precise date of intrusion, the volume of data taken, or whether systems were encrypted—have been made public. The number of individuals whose information may have been involved is listed as unknown. At present the listing itself constitutes an unverified claim by the threat actor; independent confirmation of the full scope of the incident has not been published.
Who is dragonforce?
Dragonforce is a ransomware operation that has appeared in public threat reporting as a group that both encrypts victim systems and exfiltrates data, then pressures organisations by threatening to publish stolen material on dedicated leak sites. Like many contemporary ransomware crews, it is understood to operate with a degree of specialisation—affiliates or partners may handle initial access while core operators manage encryption tooling and negotiation. Public accounts of its activity describe the familiar double-extortion pattern: data theft followed by a countdown on a leak site if payment is not made. The group’s listing of Pryor Morrow should be read as its own claim rather than as independently verified fact about this particular victim.
Who is Pryor Morrow?
Pryor Morrow is a firm specialising in architecture, engineering and interior design. Its work focuses on schools, government facilities and recreational buildings. Public descriptions of the practice emphasise long-term client relationships, community-oriented design and a team whose combined experience exceeds two hundred years. Firms of this type routinely hold architectural drawings, engineering calculations, project correspondence, contracts, and personal data belonging to employees, consultants and sometimes end-users of the buildings they design. Because many of their clients are public-sector or educational institutions, the confidentiality of plans and related documentation can carry security and privacy implications beyond ordinary commercial sensitivity. A breach involving such a practice therefore matters both to the organisation’s own operations and to the wider set of people and institutions connected to its projects.
What was likely exposed
The only data category named in the available reporting is “internal files exfiltrated in a ransomware attack.” No inventory of file types, no count of records, and no confirmation of whether personal identifiers, financial details or project-specific sensitive material were included has been published. Organisations in architecture and engineering typically maintain design files, client communications, employee records, vendor contracts and administrative documents. Whether any of those categories were among the material claimed by dragonforce remains unconfirmed. Readers should treat the precise contents as unknown until more detailed disclosure appears.
What's at stake
For individuals whose contact details, employment information or project-related personal data may have been present, the practical risks include unwanted contact, phishing attempts that leverage knowledge of real projects, or identity-related misuse if identifiers were among the files. For the firm itself, exposure of internal files can affect client trust, contractual obligations around confidentiality, and the integrity of ongoing design work. Public-sector and educational clients may face additional scrutiny if building plans or security-related documentation were involved. Because the scale of the incident and the exact data types remain undisclosed, the concrete impact on any single person or project cannot yet be quantified; the risk is real but currently unmeasured.
If your data was in this claimed breach
If you have a past or present connection to Pryor Morrow—as an employee, client, consultant or project stakeholder—consider the following practical steps:
- Monitor financial and email accounts for unexpected activity or targeted phishing that references real projects or colleagues.
- Enable multi-factor authentication on any accounts that share credentials or recovery information with work-related services.
- Request a free credit or identity-monitoring check if you believe personal identifiers may have been stored in the firm’s systems.
- Retain copies of any breach notifications you receive and note the date for future reference.
- Run a free exposure scan of your email address against known breach data sets to see whether your information has already appeared in other incidents.
Public detail on this incident remains limited. Further official statements from the firm or independent verification of the dragonforce claim would be needed before a fuller picture of the exposure can be drawn.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
A.S.A.P. Restoration Listed by dragonforce Ransomware GroupKing City Lumber Listed by dragonforce Ransomware GroupDivision 10 Listed by dragonforce Ransomware GroupShelbra International Listed by dragonforce Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Pryor Morrow Listed by dragonforce Ransomware Group →
Publicly posted by dragonforce — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.