AFWorkshop Listed by Deadlock Ransomware Group
If you are a customer of AFWorkshop, here’s what is being claimed, and what it would mean for you.
AFW an international architectural and design firm based in Singapore. Formerly known as Andy Fisher Workshop, the firm has been operating since 2004. They are a multi-disciplinary practice that works on a variety of large-scale and boutique projects across Asia and beyond.
— from Deadlock’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
On July 10, 2026, architectural and design firm AFWorkshop appeared on the leak site of the Deadlock ransomware group. The company, formerly known as Andy Fisher Workshop and based in Singapore, had internal files exfiltrated during a ransomware attack. While the exact number of people whose information may have been exposed remains unknown, anyone whose personal or professional data was stored in the firm’s systems could be affected.
Watch AFWorkshop
Get alerted the next time AFWorkshop files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about AFWorkshop’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals — $499/mo or $4,990/yr (indicative estimate).
Reported Details of the Breach
Public reporting indicates that Deadlock claims to have stolen internal files from AFWorkshop’s networks. The firm, which has operated since 2004, works on large-scale and boutique projects across Asia. Available reporting describes the incident as a typical ransomware operation in which attackers gain access, exfiltrate data, and later threaten to publish it if demands are not met. No confirmed total of records exposed has been released, and the precise types of information contained in the files have not been publicly detailed beyond the broad description of internal documents.
Why This Matters for You and Your Family
When an architecture or design firm is breached, the files often contain contracts, client contact details, addresses, phone numbers, email accounts, and sometimes copies of identification documents. If your home, office, or project was handled by AFWorkshop, your personal information may now sit in a ransomware leak repository. Credential leaks from such incidents frequently cascade into account takeovers that reach far beyond the original breach. For families this can mean sudden exposure of children’s names, school details, or linked gaming accounts that use the same email addresses or passwords parents reuse at work.
A single leak rarely stays isolated. Once data appears on a ransomware site, it is quickly scraped by other criminals who combine it with information from earlier breaches to build detailed profiles.
The Doxxing and Identity-Chain Risk
Ransomware groups like Deadlock do not need to publish every file to cause harm. Even partial leaks of client lists or project folders can give attackers the starting points for doxxing chains. A leaked work email can be matched to a personal social-media handle, then to a child’s gaming username, then to a home address. These identity chains allow criminals to harass, impersonate, or extort individuals long after the original corporate incident fades from headlines. Children’s gaming accounts are especially vulnerable because parents often share passwords or recovery emails across work, personal, and family use.
Deadlock Ransomware Group Track Record
Public reporting attributes the Deadlock ransomware group with operations that emerged in recent years. The group has targeted organizations across multiple sectors, using a playbook that typically involves initial access through phishing or exploited vulnerabilities, followed by data exfiltration and extortion via leak sites. Their approach combines encryption of victim systems with the public shaming of companies that refuse to pay, a pattern seen in attacks on other mid-sized firms whose client data held personal information.
What to do
- Run a DoxxScan to map every link between your handles, emails, phone numbers, and real identity, with cleanup handled by the specialists.
- Rotate any password you used at AFWorkshop or related professional accounts anywhere it has been reused, and switch on 2FA through an authenticator app rather than text messages.
- Enable continuous DoxxScan monitoring across 13.1B+ breach records and 100+ platforms so the next exposure of your information is caught in hours, not months.
- Cover the household with DoxxScan family coverage that extends to dependents and children’s gaming accounts that often chain back to the same addresses or emails.
- Let the remediation specialists perform hands-on takedown requests across data brokers and leak sites on your behalf.
The speed with which ransomware data moves from leak sites into broader criminal ecosystems means families cannot afford to wait for confirmation that their information was included. Starting protective steps now limits how far any single breach can reach. DoxxScan by GalaxyWarden delivers continuous monitoring across 13.1 billion+ breach records and more than 100 platforms, AI-powered identity-chain mapping that connects online handles to real identities, and hands-on remediation by specialists who manage takedowns for you and your entire household, including children’s gaming accounts that are frequently swept into these cascades.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
Report details & sourcing
Related breaches
FBC Listed by Deadlock Ransomware Group
Furniture Bargaining Council in South Africa. This is the tariff council for the furniture, mattress…
Shaheen Law Group Plc Listed by Deadlock Ransomware Group
Family law firm, established 1995 by Victor A. Shaheen (†2025 - the General Assembly of Virginia hon…
Federis Abogados Listed by Booba Project Ransomware Group
Law Practice Stolen data: 61 GB.…