Menu
Browse

Cyber Incident Victim: Turner Construction

Date

Jul 2026

Location

United States of America

Status

Ongoing

Updated

2026-08-23 06:32

Timeline
Occurred
Jul 2026
Discovered
Jul 2026
Disclosed
Jul 2026
Resolved
Pending
Summary

Turner Construction disclosed a data breach involving unauthorized access to its systems that exposed personal data such as Social Security numbers, salaries, dates of birth, bank account details and possibly passport numbers. The ransomware group Payouts King claimed responsibility, asserting it had taken 27.2 terabytes of data including engineering documents, military project files, contracts, non‑disclosure agreements and materials covered by International Traffic in Arms Regulations. The company notified at least 6,098 affected individuals, offered multi‑year identity protection services, and faces investigations by law firms seeking plaintiffs for possible class‑action lawsuits.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 0 techniques
Threat Actor Type Location
1 actor Available to members Available to members

Description

Turner Construction notified at least 6,098 individuals on Tuesday of a data breach that included Social Security numbers, salaries, dates of birth and bank account information for direct deposit. Some files may also have contained individuals’ passport numbers, the filing said. A Turner investigation determined there had been unauthorized access to the firm’s systems between July 2 and July 15, per the filing. The firm confirmed on July 27 that files containing personal information were accessed without authorization. Turner also reported that at least 38 Vermont residents were affected by the breach, according to the Office of the Vermont Attorney General.

Cyber Incident Image

Ransomware group Payouts King claimed responsibility and said the compromised data went beyond personal information, including engineering documents, military project files, contracts and non-disclosure agreements, among other records. According to ClaimDEPOT, Payouts King first posted information about an unidentified victim on July 24, before identifying Turner on Aug. 11. The group posted via a Tor network site, which masks users’ locations and identities, claiming it had obtained 27.2 terabytes of data. In addition to the types of files listed by the California attorney general, Payouts King claimed it accessed documents protected by International Traffic in Arms Regulations, a set of U.S. government rules regarding the export and import of military items, technology and services.

Upon discovering unauthorized access to certain systems, Turner engaged leading third-party cybersecurity and forensic experts to investigate. They continue to conduct a detailed review of the files involved. Turner is notifying individuals and other parties as necessary and is providing complimentary identity protection services. Turner is offering to provide identity protection services for five years through IDShield and IDX, according to the notices sent out to affected individuals filed with the California AG’s office. One of the two notices designated a Nov. 18 deadline to enroll. Several law firms posted notices of investigations into the Turner incident, seeking plaintiffs for potential class action lawsuits. Several construction-related domains have been targeted by threat actors recently, according to an Aug. 6 post on Google’s Threat Intelligence blog that designates potentially compromised sites.

Sources
Sources available to members
1 source