Stoss Landscape Urbanism Listed by akira Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Stoss Landscape Urbanism was listed by the akira ransomware group on October 10, 2025, with internal files reported as exfiltrated. Individuals should check whether their information was involved and take protective steps if necessary.
On October 10, 2025, the ransomware group known as akira listed Stoss Landscape Urbanism on its leak site, claiming to have exfiltrated more than 76GB of internal files. For employees, clients, and partners whose personal details may sit inside those files, the practical stakes are immediate: the possibility that passports, Social Security numbers, emails, phone numbers, NDAs, and other confidential records could be published or sold. Public detail remains limited; the number of people affected is unknown, and independent confirmation of the full contents has not been released. Still, the listing alone means anyone connected to the firm should treat the risk as real until proven otherwise.
This article sets out only what is known from the public record of the incident, places it in the context of how akira typically operates, and outlines the concrete steps people can take if they believe their information was involved.
Breaking down the breach
According to the reported listing dated October 10, 2025, akira claims responsibility for a ransomware attack against Stoss Landscape Urbanism in which internal files were exfiltrated. The group stated it was ready to upload more than 76GB of data and described the material as containing employees and customers information, including passports, Social Security Numbers, emails, phones, confidential information, NDAs, and other documents with detailed personal information. No independent verification of the file volume, the exact date of intrusion, the initial access method, or the total number of individuals affected has been made public. The people-affected figure remains unknown. The listing itself constitutes an unverified claim by the group rather than a confirmed forensic finding.
What is established is that the incident was framed by the attackers as a double-extortion event: data taken and held under threat of publication. Beyond that claim and the organization name, further operational details—such as whether encryption of systems also occurred, whether a ransom was demanded or paid, or whether any data has already been released—are undisclosed in the available record.
Inside akira
Akira is a well-documented ransomware operation that emerged in early 2023 and has since conducted numerous attacks across North America and Europe. The group typically employs a double-extortion model: after gaining access, operators exfiltrate sensitive files, encrypt systems where possible, and then threaten to publish the stolen data on a dedicated leak site if payment is not made. Public reporting has linked akira to the use of compromised credentials, exploitation of known vulnerabilities in remote-access tools, and living-off-the-land techniques once inside a network. The group has previously targeted professional-services firms, manufacturing companies, and other mid-sized organizations that hold concentrated volumes of personal and commercial records.
Akira’s leak-site postings serve both as pressure on the victim and as advertising for the group’s capabilities. In the present case, the listing of Stoss Landscape Urbanism follows that established pattern. No additional statements by the group about this specific victim—beyond the claim of more than 76GB of internal files containing the categories of personal and confidential material already noted—appear in the public facts. Claims made on such sites should be treated as assertions by the threat actor until corroborated by independent investigation.
Stoss Landscape Urbanism and its sector
Stoss Landscape Urbanism is a design practice that specializes in landscapes and social spaces intended to promote resilience, vitality, and equity. Its projects span downtown plazas, parks, waterfronts, campus institutions, and mixed-use residential areas. Firms of this type routinely handle employee personnel files, client contracts, project documentation, financial records, and correspondence that may contain personal identifiers of staff, consultants, municipal partners, and private clients.
Because landscape-urbanism work often intersects with public agencies, educational institutions, and residential developers, the data held can include both ordinary business records and more sensitive personal information collected during hiring, contracting, or community-engagement processes. A breach at such an organization is consequential precisely because the firm sits at the intersection of professional services and public-facing projects; any exposure of employee or customer data can affect individuals who never expected their details to leave the firm’s systems, and it can also disrupt ongoing design and construction timelines that depend on confidential agreements.
The information in question
The available facts state that internal files were exfiltrated in a ransomware attack. The group’s own claim, as reported, asserts that the material includes employees and customers information—specifically passports, Social Security Numbers, emails, phones—plus confidential information, NDAs, and other documents with detailed personal information, totaling more than 76GB. These categories are presented as the group’s description; they have not been independently itemized or confirmed in the public record. The exact contents therefore remain unconfirmed.
Organizations of this kind typically store personnel records, payroll data, client contact lists, signed agreements, project drawings, and correspondence that may embed personal identifiers. Without a verified inventory, it is not possible to state which specific fields or documents were taken. Readers should regard the listed data types as claimed rather than proven, while recognizing that the presence of any of those categories would create material risk.
What's at stake
For individuals whose information may have been included, the concrete risks include identity theft, fraudulent account openings, targeted phishing that references real personal details, and long-term exposure of government-issued identifiers such as Social Security numbers or passport data. Even email addresses and phone numbers can be weaponized for social-engineering attacks. NDAs and other confidential documents, if published, could also create legal or reputational complications for the people named in them.
For the organization itself, the stakes include potential regulatory notification obligations, contractual liabilities to clients and partners, operational disruption while systems are restored, and erosion of trust among employees and the communities it serves. Because the number of affected people is unknown and the full data set is unconfirmed, the precise scale of these risks cannot yet be quantified; the prudent posture is to assume that any individual whose data was held by the firm could be affected until further clarity emerges.
If your data was in this claimed breach
If you are a current or former employee, client, or partner of Stoss Landscape Urbanism, begin by monitoring financial accounts and credit reports for unexpected activity. Consider placing a fraud alert or credit freeze with the major credit bureaus, especially if Social Security numbers or passport details may have been involved. Change passwords on any accounts that reused credentials associated with the firm, and enable multi-factor authentication wherever it is available. Be alert to phishing messages that reference the firm or personal details that only an insider would know.
You can also run a free exposure scan of your email address to check whether that address has already appeared in known breach data sets. Keep records of any notifications you receive from the firm or from regulators, and follow official guidance once it is issued. Public detail on this incident remains limited; staying informed through verified channels and taking basic protective steps is the most practical response available at present.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Alliance Roofing Listed by akira Ransomware GroupHintenberger GmbH Listed by akira Ransomware GroupRafael Construction Listed by akira Ransomware GroupFriis & Moltke Listed by akira Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Stoss Landscape Urbanism Listed by akira Ransomware Group →
Publicly posted by akira — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.