Cybersecurity

Your CAD Files Are the Real Ransom: Lessons from Paragon Store Fixtures

Interlock listed Paragon Store Fixtures on or about July 17, 2026, with actor claims about design IP, contracts, and client identities—still a leak-site claim without confirmed org disclosure in Breach House's Sept. 1 check. For exhibit and fixture SMBs, CAD and brand IP are the crown jewels.

For custom display and exhibit fabricators, the scariest ransomware outcome is not only locked shop-floor PCs. It is a leak that names clients, dumps CAD and interior plans, and puts partnership paperwork on a dark-web card. On or about July 17, 2026, the Interlock ransomware group listed Paragon Store Fixtures (paragonstorefixtures.com), according to indexes and writeups including DeXpose (July 18), hendryadrian.com, and ransomware.live.

Public claim text carried by those indexes describes the company as specializing in custom display cases, retail fixtures, and interior design for luxury stores, beauty salons, offices, restaurants, and entertainment venues. The actor statement alleges exposure of partnership agreements, company and client intellectual property, internal design files for high-end retail and luxury brands, contracts, architectural plans, and other confidential design documents—plus alleged revelation of client and project identities. That is the attacker's narrative. Treat it as a leak-site claim, not as a completed forensic report.

What third-party indexes say—and what is still pending

Breach House's index classifies the organization as U.S.-based under a retail / e-commerce label, with an employee band of 51–100, and still showed disclosure / notification as pending as of their September 1 check. In plain English: trackers saw a listing; confirmed organizational disclosure was not recorded there at that snapshot. DNS notes on ransomware.live point to Microsoft 365 mail (Outlook protection)—a common footprint for firms this size, and a reminder that email identity is often the first foothold into design shares and project folders.

Exhibit houses, trade-show fabricators, and custom millwork shops in markets like Rome and Northwest Georgia may not share Paragon's client list, but they share the data shape: CAD libraries, brand-sensitive renders, NDAs, installer accounts, and show calendars that competitors would love to see early.

Why CAD and client IP hurt worse than encryption alone

Encryption stops production until you restore. A leak of client plans, contracts, and project identities can damage trust for years—especially when work is for luxury retail, beauty, hospitality, or entertainment brands that demand discretion. The "ransom" is not only Bitcoin. It is the fear that tomorrow's unveil or roll-out is already in someone else's hands.

Shop-floor PCs, shared design drives, and vendor/installer logins often sit flatter than people think. One compromised mailbox or a design share mapped for "everyone in production" can turn a phishing click into an IP incident.

Clear takeaway

Your CAD files and client brand IP are the real ransom. Segment design shares, lock down Microsoft 365 with MFA, constrain vendor and installer accounts, keep offsite immutable backups of project files, and apply least privilege on shop-floor PCs.

Actions to take this week

  1. Segment design shares from general file servers. Separate active project CAD, client brand kits, and archived jobs; limit who can copy bulk folders.
  2. Turn on MFA for every Microsoft 365 mailbox and admin role. Phishing against Outlook remains a common path into project email and SharePoint/OneDrive design drops.
  3. Inventory vendor and installer accounts. Temporary access for install crews and freelancers should expire; no shared "shop" passwords for client portals.
  4. Keep offsite, immutable backups of project files. Versioned object storage or locked backup copies of CAD and final deliverables matter as much as server images.
  5. Apply least privilege on shop-floor PCs. Production machines should not hold the full client IP library or domain-admin rights "for convenience."

Brotherly Technology works with manufacturers, fabricators, and professional SMBs across Northwest Georgia to protect the files that make the business valuable—not only the servers that keep the lights on. The Interlock listing for Paragon Store Fixtures is a clear signal for exhibit and fixture shops: assume criminals want your drawings and your client names, and build controls that make that haul hard to grab and hard to restore from nowhere.

Sources:

One accountable technology partner.

Tell us what's slowing your team down. We'll show you exactly how we'd fix it — no pressure, no jargon.

Book a Free Consultation
Book a Free Consultation