Data breach reported for Harrison Design Associates

UpGuard Team
UpGuard Team
February 26, 2026

Key Facts: Harrison Design Data Breach

  • Date reported: February 25, 2026.
  • Unauthorized access identified: December 16, 2025 (activity occurred between December 14 and December 16, 2025).
  • Target entity: Harrison Design (harrisondesign.com).
  • Source of breach: INC Ransomware group (Incransom).
  • Data types: Names and Social Security numbers; attackers claim to have exfiltrated 100GB of sensitive data.
  • Status: Confirmed; a comprehensive review was finished on January 9, 2026, and notification letters were mailed starting January 16, 2026.
  • Severity: Medium; while the firm is not aware of actual misuse, the exfiltration of Social Security numbers by a known ransomware group presents a high risk of identity theft.

Start continuous breach monitoring with UpGuard.

What happened in the Harrison Design data breach?

Harrison Design (harrisondesign.com) reported a data breach incident on February 25, 2026. The organization detected unusual activity within its network between December 14, 2025, and December 16, 2025. The INC Ransomware group has since claimed responsibility for the cyberattack.

Following an investigation, the company determined that an unauthorized individual may have copied certain personal information. The incident is classified as medium severity, indicating a moderate level of risk to the affected parties. Harrison Design completed a review of the impacted data on January 9, 2026, and began the process of notifying those involved. While the specific data types often vary in such events, this incident involved the potential copying of 100GB of sensitive records.

Who is behind the incident?

The ransomware group known as INC Ransomware (Incransom) has claimed responsibility for the attack. This group is known for exfiltrating data and threatening its release to extort payments from high-profile organizations.

Impact and risks for Harrison Design customers

For customers and individuals associated with Harrison Design, the primary risks include potential identity theft, credential stuffing, and phishing campaigns. If personal data, such as Social Security numbers, was successfully copied by an unauthorized party, it could be used to facilitate fraudulent transactions or gain access to other sensitive accounts. Users should remain cautious of any unsolicited communications requesting further personal details.

Common outcomes of such breaches include unauthorized account access and financial fraud. To mitigate these risks, individuals should update their passwords, monitor their bank statements, and check credit reports regularly. Maintaining transparency regarding the breach allows those affected to take proactive steps in securing their digital identities.

How to protect against similar security incidents

Scan your domain for vulnerabilities in minutes

Frequently asked questions

What happened in the Harrison Design security breach?

On February 25, 2026, Harrison Design (harrisondesign.com) disclosed a security breach. According to initial reports, an investigation into unusual network activity revealed that certain personal information, specifically names and Social Security numbers, may have been copied by an unauthorized individual.

When did the Harrison Design breach occur?

The Harrison Design breach occurred between December 14 and December 16, 2025. It was first detected by the company on December 16, 2025, and publicly reported in February 2026 following a forensic review.

What data was exposed?

The investigation determined that the data potentially impacted included names and Social Security numbers. Threat actors have claimed to possess a much larger dataset totaling 100GB of exfiltrated information.

Is my personal information at risk?

If you are an employee or associate of Harrison Design, there is a possibility your personal information was affected. Incidents involving Social Security numbers carry a high risk of identity theft. Stay alert for official notification letters, which contain information on credit monitoring services being offered.

How can I protect myself after this data breach?

  • Change passwords for all sensitive accounts
  • Enable multi-factor authentication (MFA) where possible
  • Monitor financial accounts for unauthorized activity
  • Stay alert for phishing attempts via email or phone
  • Use data breach monitoring tools to track your information

What steps should companies take after being impacted by this breach?

Harrison Design is working to secure its systems and notify affected parties. The company is providing guidance on protective actions, reviewing security measures, and deploying attack surface management to strengthen its defenses.

How secure is Harrison Design?

Harrison Design (harrisondesign.com) is a premier full-service architecture, interior design, and landscape architecture firm.
  • Check icon
    View our free preliminary report on Harrison Design’s security posture
  • Check icon
    13 risk factors, including email security, SSL, DNS health, open ports and common vulnerabilities
https://harrisondesign.com/
Security ratings
Deliver icon

Sign up for our newsletter

UpGuard's monthly newsletter cuts through the noise and brings you what matters most: our breaking research, in-depth analysis of emerging threats, and actionable strategic insights.
UpGuard customer support teamUpGuard customer support teamUpGuard customer support team

Protect your organization

Get in touch or book a free demo.
Free instant security score

How secure is your organization?

Request a free cybersecurity report to discover key risks on your website, email, network, and brand.
  • Check icon
    Instant insights you can act on immediately
  • Check icon
    Hundreds of risk factors including email security, SSL, DNS health, open ports and common vulnerabilities
Website Security scan resultsWebsite Security scan rating