Pelli Clarke & Partners, a prominent architecture firm based in New Haven, Connecticut, has notified individuals that their personal information may have been compromised following unauthorized access to the firm’s computer network. Architecture and design firms often maintain extensive records on employees, contractors, and business partners, and any unauthorized access to that data raises real concerns for the people whose information was stored on the affected systems.
Pelli Clarke & Partners’s Data Breach Investigation
According to a notice filed with the Massachusetts Office of Consumer Affairs and Business Regulation, Pelli Clarke & Partners was notified of suspicious activity within its computer network on or around July 3, 2026. The firm stated it took immediate action to secure its network and began an investigation with the assistance of specialists. On July 30, 2026, the firm determined that certain files had been taken from its network, and a subsequent review confirmed that personal information was included among the affected files. Pelli Clarke & Partners has stated it has no evidence that any personal information has been misused for fraud or identity theft as a result of the incident, but is nonetheless notifying and offering protective resources to those individuals whose information was involved.
Security researchers have reported that a company under the Pelli Clarke Pelli/Pelli Clarke & Partners name was listed by a ransomware group in connection with a claimed data theft around the same period as this incident, though the firm’s own notice to Massachusetts regulators does not confirm the specific cause. When a ransomware or extortion group claims responsibility for stealing data, it typically means the stolen files may be published or sold if a ransom demand is not met, which is part of why affected individuals are encouraged to remain vigilant even when a company reports no confirmed misuse yet.
Firms in professional services industries like architecture and design are increasingly targeted by cybercriminals not because of the industry itself, but because these firms hold valuable business records, client contracts, and employee personal information that can be resold or leveraged for further attacks. The time between initial detection of suspicious activity and a final determination of what data was taken, in this case roughly four weeks, is a common pattern in network intrusion investigations, since forensic teams need time to fully assess what an attacker accessed or exfiltrated before a company can respond accurately to those affected.
Pelli Clarke & Partners is offering complimentary identity protection services through Kroll to individuals affected by this incident, a step commonly taken by companies responding to a confirmed data exposure. Enrolling in these services and monitoring credit reports closely in the months following notification is one of the most effective ways affected individuals can catch any attempted misuse of their information early.
When Did This Breach Occur?
Pelli Clarke & Partners was notified of suspicious network activity on or around July 3, 2026, and determined on July 30, 2026, that files containing personal information had been taken from its network.
What Information Was Breached?
Pelli Clarke & Partners has not publicly itemized the complete list of data elements affected in its filed notice, which used a template placeholder for the specific data categories. Individuals who receive a direct notification letter from the firm should review it carefully, as it may specify the exact type of personal information involved in their case.
What You Can Do
Anyone notified by Pelli Clarke & Partners should consider taking the following steps:
- Enroll in the complimentary Kroll identity protection services referenced in your notification letter
- Review account statements and credit reports for unfamiliar activity
- Place a fraud alert or credit freeze with the three major credit bureaus
- Be cautious of unsolicited emails or calls referencing Pelli Clarke & Partners or your accounts
- Report any suspected identity theft to local law enforcement and your state Attorney General
File a Data Breach Lawsuit Against Pelli Clarke & Partners
If you received a notice that your personal information may have been exposed in the Pelli Clarke & Partners data breach, you may have legal options available to you. Companies entrusted with personal information have a responsibility to protect it, and when that trust is broken, affected individuals deserve to understand their rights.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.