Cyber & AI intelligence
Wasteland.
Briefs indexed2880
Issues29
Published Mondays07:30 CT
▣ Breach PELLI-CLARKE-PARTN 2026-09-26

Pelli Clarke & Partners: Personal Data Stolen in July 2026 Network Intrusion

"Pelli Clarke & Partners, the New Haven, Connecticut architecture firm known until recently as Pelli Clarke Pelli Architects, has notified individuals that files containing personal information were taken from its…"

Pelli Clarke & Partners, the New Haven, Connecticut architecture firm known until recently as Pelli Clarke Pelli Architects, has notified individuals that files containing personal information were taken from its network. According to a notice filed with the Massachusetts Office of Consumer Affairs and Business Regulation, as summarised by Class Action U, the firm spotted suspicious activity on or around July 3, 2026 and confirmed on July 30 that data had been removed. No public source gives the number of affected individuals, names the attacker, or explains how the attacker got in. Class Action U is advertising a class action over the breach. None of the eight sources available for this brief is a primary or established-press source, so the details below should be read with that in mind.

What Happened

The timeline comes from a single aggregator, Class Action U, which relies on the firm's Massachusetts regulatory filing:

The firm says it has no evidence that the information has been misused for fraud or identity theft.

Company profile data from LinkedIn (S2, S3) puts Pelli Clarke & Partners at 70 to 80 employees and $20M to $30M in annual revenue. It has offices in New Haven and New York and staff in eight countries, including the US, China, Italy, the Netherlands and Chile. A 2015 press release (S4) confirms the practice was founded in 1977 by Cesar Pelli, Fred Clarke and Rafael Pelli and has designed large public projects such as Chicago's McCormick Place Event Center.

What Was Taken

The public record here is thin. According to Class Action U, the filed notice describes the exposed data only as names in combination with other personal information, without listing which data types were involved. No source gives a record count or a data volume, so this brief does not estimate either.

The sources also disagree on who was affected. Class Action U's summary says "clients" of the firm. Its own narrative, though, points out that architecture firms hold large amounts of data on employees, contractors and business partners. Until the full notice letter is published, the affected group should be treated as unconfirmed. For a firm of this size, staff and HR records would be a plausible target.

Why It Matters

Possible ransomware link, unconfirmed. Class Action U says security researchers have reported that an entity under the Pelli Clarke Pelli or Pelli Clarke & Partners name was listed by a ransomware group around the same time. The group is not named, and the firm's notice does not mention ransomware or extortion. This claim comes from one OTHER-tier source and should be treated as unverified.

Beware the Clop link. A separate August 2026 report (S5) describes the Clop gang listing 43 victims tied to CVE-2026-12569, an improper input validation flaw in internet-exposed PTC Windchill and FlexPLM servers. The victims include Shell, which Clop says lost 89GB of engineering drawings and project plans. Design and engineering firms fit that victim profile. However, nothing in the available sources ties Pelli Clarke & Partners to Clop or to that campaign. Analysts should not draw that link without further evidence.

Mid-sized professional services firms are high-value, low-defence targets. An architecture practice of about 75 people holds personal data on staff and clients alongside sensitive building designs, security layouts and client project data. Attackers value both kinds of data. A firm this size rarely has an in-house security operations function.

Regulatory context. Two sources (S7, S8) discuss the FTC Safeguards Rule's 30-day breach-reporting rule, which took effect May 13, 2024 and covers financial institutions, including tax and accounting firms, when unencrypted data on 500 or more consumers is taken. An architecture firm is unlikely to be covered by that rule. Its obligations run through state breach notification laws, such as the Massachusetts filing cited above. Nothing in the sources connects the firm to the New York HCRA elector list (S6).

The Attack Technique

Not publicly disclosed. The notice as reported says only "unauthorized access" to the network, followed by file exfiltration. It does not name an initial access vector, malware family, exploited vulnerability or actor. The pattern of data theft confirmed weeks after detection matches modern double-extortion and data-theft-only operations. Beyond that, the method remains unknown.

What Organizations Should Do

  1. Inventory and patch internet-facing systems. This includes VPNs, file-transfer tools, and PLM or document-management servers such as Windchill, which is already a confirmed mass-exploitation target in 2026 (S5).
  2. Watch for large outbound data transfers. The gap between detection and confirmed theft in this case shows how hard exfiltration can be to scope after the fact. Egress monitoring and DLP alerting on bulk transfers make that job much easier.
  3. Separate HR and client personal data from project file shares. Keep personal data in restricted stores with their own access controls and logging.
  4. Encrypt sensitive data at rest and keep the keys protected. Beyond reducing harm, encrypted data with a safe key can change whether some notification regimes are triggered (S7).
  5. Check ransomware leak sites for your own name. Threat-intel feeds can surface a listing before your internal investigation confirms data loss.
  6. Prepare notification playbooks per state. Firms with staff and clients in many places need pre-mapped notice obligations and timelines.

Sources: Pelli Clarke & Partners Data Breach Lawsuit | Rafael Pelli | Kim DiRaffaele | PR Junction: Groundbreaking for Pelli Clarke Pelli Architect's new... | Clop's 43-victim batch puts PLM servers, not file transfer, at the... | HCRA Elector List - PC - PH - September 1, 2026 | Does Encryption Exempt a Tax Firm From FTC Breach Notice? | Data Breach Notification Obligations for CPA Firms