Major Contractors Experienced System Breaches Since July 2026

Unauthorized access at firms like Turner Construction highlights security gaps within critical government infrastructure.

Updated on Sept. 29, 2026 in Cybersecurity

Isometric editorial illustration showing a steel I-beam next to a lattice of optical cables, representing systemic cybersecurity risks in infrastructure.
Three major U.S. construction contractors, including Turner Construction and AECOM, reported unauthorized system access since July 2026, exposing sensitive government project documents. AI Illustration. Upload story photo >

Live Poll

Do you trust that most businesses you deal with take adequate steps to prevent data breaches?

Three major U.S. contractors—Turner Construction, Kiewit, and AECOM—faced unauthorized system access beginning in July 2026. These breaches exposed sensitive information, including government project plans protected by International Traffic in Arms Regulations.

Why it matters

The construction sector serves as a target because it houses military installation designs and state secrets, yet it has historically underinvested in cybersecurity. This trend is exacerbated by the rise of generative AI, which attackers use to automate sophisticated business email compromise schemes.

Construction firms ranked cyber threats 10th among business concerns, while breach investigation costs for mid-sized companies can exceed hundreds of thousands of dollars. Meanwhile, Granite Construction distinguished itself by achieving Cybersecurity Maturity Model Certification Level 2 in 2026.

The players

Turner Construction

A major construction firm providing complex project delivery services that was targeted in the 2026 data breaches.

Kiewit

A large-scale construction and engineering firm involved in critical infrastructure that experienced unauthorized system access.

AECOM

A global infrastructure consulting firm providing design and construction management services that faced recent cybersecurity compromises.

Granite Construction

A heavy civil infrastructure contractor that achieved Cybersecurity Maturity Model Certification Level 2 in 2026.

The details

Attackers leveraged business email compromise—a scheme where criminals gain control of user accounts to send fraudulent invoices—to bypass traditional defenses. These operations are increasingly supported by generative AI agents, which allow hackers to automate hostile network reconnaissance and craft phishing emails with error-free grammar. The unauthorized access targeted internal systems, specifically compromising sensitive data including passport information, bank account details, and International Traffic in Arms Regulations documentation.

Timeline

  1. July 2026: Unauthorized access incidents began at three major contractors.

  2. 2026: Cyber threats were identified as the top business concern nationwide.

The Tech Race

The construction industry is trailing behind federal security expectations, evidenced by the contrast between widespread vulnerabilities and the implementation of the Cybersecurity Maturity Model Certification. Granite Construction's recent certification marks a rare, high-standard milestone in a sector historically lagging in risk mitigation.

Government contractors must now navigate stricter compliance requirements to protect sensitive specifications against AI-driven threats. Businesses in the sector should prioritize security investments as investigation costs for breaches can quickly escalate to hundreds of thousands of dollars.

The takeaway

The sector's reliance on legacy security systems is failing against automated AI threats, creating a urgent need for updated network hygiene. Stakeholders should monitor for new compliance mandates or industry-wide security alerts from federal agencies as contractors attempt to close these vulnerabilities.

Further reading

For more on evolving threat landscapes, visit Cybersecurity.

Source note: This article includes information reported by Construction Dive.

Live Poll

Do you trust that most businesses you deal with take adequate steps to prevent data breaches?