On December 21, 2025, architectural firm PAUAT Architekten appeared on the leak site of the safepay ransomware group. The Austrian company, based in Wels and founded in 1999, may have had internal files stolen during a ransomware attack. While the exact number of people whose information may have been exposed remains unknown, any client, employee, or vendor whose personal or financial details passed through the firm’s systems could now be at risk.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch pau.at
Get alerted the next time pau.at files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about pau.at’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that safepay posted evidence of successful data exfiltration from PAUAT Architekten. The firm specializes in architecture and is led by architect Heinz Plöderl. Internal files were taken; no further technical details about the initial access method or the precise volume of data have been publicly confirmed. The listing appeared on the group’s onion site, a common venue for ransomware operators to pressure victims after encryption and exfiltration.
Why This Matters for You and Your Family
When a local business like an architectural practice suffers a breach, the impact often reaches ordinary families. You or your spouse may have shared addresses, phone numbers, email accounts, or payment information during a home renovation, planning application, or property dispute. Children’s names sometimes appear in family correspondence. Once those records leave the company’s control, they can be traded or sold on underground forums. Personal data from architectural clients frequently includes enough detail to support identity theft, phishing, or harassment. Even if you never signed a contract with PAUAT, shared suppliers or subcontractors could have passed your information along.
The Doxxing and Identity-Chain Implications
Stolen internal files rarely contain only one type of record. A single spreadsheet can link your home address to email accounts, phone numbers, and project notes that mention family members. Attackers chain these fragments with data from earlier breaches to build a complete profile. A gaming username belonging to your child, once tied to the same household address, can lead to account takeovers on Steam, Roblox, or Discord. Credential leaks of this nature frequently cascade into doxxing campaigns where real-world identities are published alongside private conversations or financial details. The longer the chain grows, the harder it becomes to contain.