The Cannon Corporation
bd_a8d7c520be3f9002 · schema v1 · pii pii-v1
Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Dunghill on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
CannonDesign is a global architecture, engineering and consulting practice that provides services for a range of project types, including hospitals and medical centers, corporate headquarters and commercial office buildings, higher education and PK-12 education facilities, hotels and hospitality, mixed-use, sports facilities, and science and research buildings. In 2017 and 2019, Fast Company named CannonDesign one of the 10 most innovative architecture firms in the world.
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Sep 26, 2023
Claim posted
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Claim → filing
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- Illinois State AGbd_93b34f69bc60fe912024-08-01 · +310dCandidate
- Indiana State AGbd_13b4cd69402e1f192024-08-19 · +328dVerified
- Montana State AGbd_254fc6798c6e3f3a2024-08-19 · +328dVerified
- Vermont State AGbd_47c8afecbf0e0a572024-08-19 · +328dVerified
Show 6 more filings ↓Show fewer ↑up to 356d gap
- Massachusetts State AGbd_55d874d019872f082024-08-19 · +328dVerified
- Maine State AGbd_56974add996bba7d2024-08-19 · +328dVerified
- New Hampshire State AGbd_6075ef2eac55c60a2024-08-19 · +328dVerified
- California State AGbd_ce1fa2f5343ac7022024-08-19 · +328dVerified
- New Hampshire State AGbd_5e25aa73e91705282024-09-16 · +356dVerified
- Massachusetts State AGbd_aca1c445e038446c2024-09-16 · +356dVerified
Filing propagation · 11 filings · 8 states
View merged incident ↗Pattern: first filing Sep 26, last Sep 16 (MA) — a 356-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- actor name
- victim claim
- ransom/leak status
- discovery date
- materiality
- notification
- affected count
- confirmed data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
dunghill
According to ransomware.live, Dunghill Leak is the data extortion site operated by the Dark Angels ransomware group, active since early 2023, targeting large enterprises across healthcare, finance, industrial, and technology sectors using a highly selective non-affiliate model, and responsible for a record-breaking $75 million ransom payment in 2024.