MEI Architects, a San Francisco architecture firm, suffered a ransomware attack by a group called Dark Project that stole about 340 GB of data, including Social Security numbers, passports, green cards, HR files, and architectural drawings. The exact number of affected individuals has not been disclosed. Anyone connected to the firm should monitor their credit reports and consider a credit freeze immediately.
| Company | MEI Architects |
|---|---|
| Industry | Other Commercial |
| Data Types Exposed | Social Security Numbers, Passport Information, Green Card Documentation, Invoices and Financial Records, HR Documents, Architectural Drawings |
| People Affected | Not Publicly Disclosed |
| Attack Method | Ransomware |
| Regulators Notified | Not Publicly Disclosed |
What Happened in the MEI Architects Data Breach?
MEI Architects, a San Francisco design firm known for commercial, residential, and public projects, has confirmed a serious cybersecurity incident. A ransomware group calling itself Dark Project has claimed responsibility. According to available reporting, the attackers stole roughly 340 GB of data, spread across approximately 130,000 files.
The breach reportedly involved unauthorized access to the firm’s internal network. Once inside, the attackers pulled a wide range of sensitive files rather than only encrypting systems. This pattern is common in modern extortion-style ransomware attacks, where data theft happens before any disruption is noticed.
The exact discovery date has not been publicly disclosed. However, notification related to this MEI Architects data breach became public in September 2026. As a result, the timeline between the actual intrusion and public awareness remains unclear to outside observers.
Because the attack involved a named threat actor group, forensic investigators likely traced the intrusion through log analysis and dark web monitoring. In addition, firms that experience this type of theft typically bring in outside cybersecurity specialists. This helps confirm the scope of stolen files and secure any remaining vulnerabilities.
Who was affected?
The individuals affected by this incident likely include current and former MEI Architects employees. In addition, clients whose personal or project information was stored on the firm’s systems may also be affected. Because the firm works with government, nonprofit, and private clients, the exposure could span multiple sectors.
At this time, the exact number of affected individuals has not been publicly disclosed. This means the full scope of the breach, including how many people had their Social Security numbers or passport data exposed, remains uncertain. Affected individuals should not assume they are safe simply because a specific count has not been released.
Given that the stolen files include HR documents, current and former staff members are a clear concern. Meanwhile, clients tied to government-linked or public infrastructure projects may also face exposure. This raises questions about the broader consequences beyond typical consumer data breaches.
What Information Was Potentially Exposed?
The scope of stolen data in this incident is unusually broad for a professional services firm. Reports indicate the attackers accessed both personal identity records and sensitive business files. Because of this mix, the risk extends beyond typical financial fraud concerns.
- Social Security numbers
- Passport information
- Green card documentation
- Invoices and financial records
- HR documents
- Architectural drawings for past, current, and in-progress projects
The presence of Social Security numbers, passports, and green cards is especially concerning. These documents are considered high-value targets for identity thieves. For example, a stolen Social Security number combined with a passport scan can allow criminals to open new financial accounts or file fraudulent tax returns.
In addition, the theft of architectural drawings raises a different kind of risk. Projects tied to government or public infrastructure, such as facilities serving veterans, could carry security or planning implications if design details become public. This is not a typical financial fraud risk, but it remains a serious concern for affected institutions.
What is the company doing?
MEI Architects has not publicly detailed every step of its response. However, incidents involving confirmed data theft typically trigger an internal investigation alongside outside cybersecurity support. This generally includes containing the breach and assessing which systems were compromised.
Because Social Security numbers and passport data were involved, the firm likely has an obligation to notify affected individuals directly. In addition, organizations facing this type of exposure often work to strengthen network defenses and monitor for further suspicious activity. Ongoing monitoring helps confirm whether stolen data appears for sale or distribution online.
What Should Affected Individuals Do?
Monitor Your Credit Reports
Anyone potentially affected by the MEI Architects data breach should check their credit reports regularly. You can request free reports from all three major credit bureaus through AnnualCreditReport.com. Reviewing these reports helps you catch new accounts or inquiries you did not authorize.
Because Social Security numbers were involved, this step matters even more. Identity thieves often wait months or years before using stolen data. Therefore, ongoing monitoring, not just a one-time check, offers the best protection over time.
Consider a Credit Freeze or Fraud Alert
Given that Social Security numbers, passports, and green card information were exposed, a credit freeze is a strong protective step. A freeze blocks new creditors from accessing your credit file. As a result, it becomes much harder for identity thieves to open new accounts in your name.
Alternatively, a fraud alert requires lenders to verify your identity before extending credit. This option is faster to set up and still offers meaningful protection. You can request either option directly through Equifax, Experian, or TransUnion.
Watch for Phishing and Impersonation Attempts
Because HR documents and personal identifiers were stolen, affected individuals may become targets of convincing phishing emails or calls. Scammers often use real personal details to appear legitimate. This makes it easier for them to trick victims into revealing even more information.
You should avoid clicking links or downloading attachments from unexpected messages. Instead, verify any suspicious communication by contacting the organization directly through a known phone number or website. When in doubt, treat unsolicited requests for personal information with caution.
Protect Passport and Immigration Documents
If your passport or green card information was included in the stolen files, extra caution is warranted. Consider contacting the U.S. State Department or U.S. Citizenship and Immigration Services for guidance on monitoring for misuse. In some cases, replacement documents may be advisable.
In addition, be alert to any unexpected communication claiming to be from immigration authorities. Scammers sometimes use stolen immigration data to run targeted fraud schemes. Because these documents are tied to your legal identity, verifying their security is worth the extra effort.
Consult a Data Breach Attorney
Given the sensitivity of the data involved, affected individuals may want to speak with a data breach attorney. An attorney can help you understand whether you qualify for compensation. Many offer free case evaluations, so there is little downside to asking questions.
Furthermore, legal counsel can help you track deadlines and evaluate options if a class action develops. Acting sooner rather than later ensures you do not miss any applicable filing windows. This step is especially useful if you notice signs of identity theft.
