AECOM
Incident posture
Timeline
Summary
A reported cyberattack on AECOM remains unconfirmed, with the hacker group Metaencryptor claiming responsibility for an intrusion involving about 1.22 TB of data. A separate dark web monitoring service listed a roughly 670GB leak attributed to BrainCipher and indexed thousands of company-linked credentials, while cautioning that the credentials may not be connected to the claimed attack. The incident may affect current and former employees, clients, and others whose information the company maintained, but the scope, data types, and number of affected people have not been publicly established.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
A reported cyberattack against AECOM first surfaced on dark web monitoring sites on or about September 17, 2026. A post published on Ransomware.live that day stated that the hacker group Metaencryptor claimed responsibility for compromising approximately 1.22 terabytes of AECOM data. The cybersecurity blog HookPhish also reported that Metaencryptor was behind the suspected attack. These reports represented attacker claims and did not establish that the alleged theft had occurred. AECOM did not publicly confirm the breach or provide details about its scope, impact, affected systems, or the number of people affected.
A separate listing on the dark web monitoring service Breachsense described an AECOM-related data leak of approximately 670 gigabytes and attributed it to a group identified as BrainCipher. Breachsense also indexed thousands of AECOM-linked credentials circulating online, including 27,434 @aecom.com accounts drawn from external breaches and 6,077 credentials tied to aecom.com itself. The listing included logins found in combination lists and infostealer malware logs, with many associated plaintext passwords. Breachsense cautioned that the credentials could belong to customers or staff and were not necessarily connected to the claimed attack. The specific data involved in the reported breach remained unconfirmed, as did the identities and total number of affected individuals. Potential exposure concerned current and former AECOM employees, clients, and other people whose personal information AECOM maintained. The reported incident created potential risks of identity theft and fraud, although no confirmed exposed data categories were publicly identified.
On September 20, 2026, Edelson Lechtzin LLP announced that it was investigating potential privacy and class-action claims arising from the reported breach. The firm stated that it was evaluating claims on behalf of individuals who received an AECOM breach notice or believed their personal information may have been exposed. No public information was provided about AECOM’s detection, containment, eradication, recovery, or notification actions. The breach and the hackers’ claims remained unconfirmed, with the true scope and consequences not publicly available.
Sources
Sources available to members: 1 source.