
Cannon Corporation, operating under the name CannonDesign, has begun notifying more than 13,000 clients of a significant data breach involving the unauthorized access and theft of sensitive information from its network. The breach occurred during an attack in early 2023, with the company only recently completing its investigation.
CannonDesign, a renowned architectural, engineering, and consulting firm, is known for its innovative work on high-profile projects such as the University of Minnesota Health Clinics and Surgery Center and the multi-purpose stadium at the University of Maryland. The firm’s recognition as one of the world’s most innovative architecture firms underscores the gravity of the incident.
The security breach occurred between January 19-25, 2023, with CannonDesign discovering the intrusion on January 25. However, it was not until May 3, 2024, that the firm completed its investigation into the breach. This investigation revealed that the attackers, identified as the Avos Locker ransomware gang, accessed and exfiltrated a wide range of personal data, including names, addresses, Social Security numbers (SSNs), and driver’s license numbers.
Despite the delayed response, CannonDesign is offering affected clients 24 months of credit monitoring through Experian to mitigate the risks associated with the exposure of their data. However, the delay in notification has raised concerns, particularly since the stolen data has been circulated online multiple times over the past year.
The Avos Locker ransomware group initially claimed responsibility for the attack on February 2, 2023, announcing that they had stolen 5.7 terabytes of data, including corporate and client files. After unsuccessful extortion attempts, the data was subsequently leaked by Dunghill Leaks, a site operated by the Dark Angels ransomware group. On September 26, 2023, 2 terabytes of this data were published online, including project schematics, client details, and other sensitive information. The dataset has since appeared on various dark web forums, including ClubHydra and Breached Forums.
CannonDesign has not publicly identified the perpetrators, but the firm confirmed that the data breach is linked to the Avos Locker ransomware attack. Despite the widespread dissemination of the stolen data, CannonDesign stated that it is unaware of any attempted misuse of the information.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543