On November 24, 2023, architecture firm Albert, Righter & Tittmann Architects, Inc. appeared on the leak site operated by the donutleaks ransomware group. The listing states that internal files were exfiltrated during a ransomware attack and warns that the full amount of data will be uploaded to a torrent server, complete with magnet URL, torrent file, and detailed listing. The firm’s website is referenced directly in the post.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Albert
Get alerted the next time Albert files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Albert’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details in the Leak-Site Posting
The donutleaks entry states that the incident began as a ransomware deployment and that attackers successfully removed internal files before encryption or public disclosure. No specific number of records or named data types such as client contracts, employee records, or financial spreadsheets is provided; the posting simply states that internal files were taken. It promises forthcoming updates with a public torrent once the full dataset is hosted. The disclosure does not mention any ransom demand figure or negotiation status. Public reporting on similar donutleaks listings indicates the group follows a double-extortion model: encryption of victim systems paired with threats to release stolen data unless payment is made.
Why This Matters for You and Your Family
When an architecture firm’s internal files reach a ransomware leak site, anyone whose personal information passed through that firm is now at elevated risk. Clients, employees, vendors, and subcontractors may find their names, addresses, Social Security numbers, banking details, or project correspondence exposed. For ordinary families this can translate into sudden spikes in identity-theft attempts, loan fraud, or targeted phishing. Even if you cannot recall working with Albert, Righter & Tittmann, shared industry networks or subcontractors mean your data could still be present. The November 24, 2023 listing removes any illusion that the breach remains contained; once torrent links appear, the files can be downloaded by anyone.
Doxxing and Identity-Chain Risks
Stolen internal files rarely contain isolated records. They often link email addresses, phone numbers, physical addresses, project notes, and sometimes scanned contracts that tie one piece of information to another. Attackers and opportunistic criminals stitch these fragments into full identity profiles. A seemingly harmless architectural drawing metadata containing your home address can be combined with an email address found in the same archive to hijack online accounts or impersonate you to banks. Credential leaks that surface in the same dataset frequently cascade into gaming-account takeovers; children’s usernames, linked parent emails, and household addresses create an unbroken chain that leads straight back to your front door. Continuous monitoring across large breach repositories is one of the few practical ways to detect these linkages before they are exploited.