By Investigative Construction Desk
Part of “The Dotted Line” Series

There is an old, grim adage deeply embedded in the modern technology sector: It is not a matter of if your digital infrastructure will be breached, but when. For decades, the construction industry—built on tangible materials, heavy machinery, and physical grit—largely viewed this digital warning as a problem reserved for Silicon Valley tech giants, financial institutions, and retail conglomerates.

That sense of detached security evaporated this past summer. A wave of high-profile cyberattacks struck three of the most prominent contracting titans in the United States: Turner Construction, Kiewit Corporation, and AECOM. Public notices, regulatory filings, and subsequent class-action lawsuits revealed that unauthorized actors had penetrated the digital perimeters of these industry giants, exposing sensitive data and laying bare a troubling reality.

Today, construction is no longer just about moving dirt, pouring concrete, and erecting steel beams. Major contractors are digital repositories housing corporate financials, employee social security numbers, banking details, and—most critically—classified blueprints and state secrets for the nation’s most sensitive military and civil infrastructure. As cybercriminals leverage artificial intelligence to automate and refine their attacks, legal experts and industry leaders warn that construction’s historically casual approach to cybersecurity has transformed the sector into one of the most vulnerable links in the national security chain.


Main Facts: High-Stakes Breaches Hit Construction Giants

The recent wave of cyber incidents has shattered the illusion that construction firms fly beneath the radar of sophisticated threat actors.

The attacks on Turner Construction, Kiewit, and AECOM underscore a terrifying shift in targets. In Turner’s case, the breach potentially compromised a treasure trove of personally identifiable information (PII), including social security numbers, banking information, and passport data. More alarmingly, the intrusion triggered national security alarms. A notorious hacker collective known as “Payouts King” publicly claimed it had successfully exfiltrated documents protected under International Traffic in Arms Regulations (ITAR)—strict U.S. federal regulations governing the export and import of defense-related technology and military items.

While Turner Construction declined to comment directly on the specific claims made by the criminal organization, cybersecurity investigators and construction law specialists emphasize that the implications stretch far beyond corporate extortion. Modern contractors design and build Department of Defense installations, intelligence facilities, and critical transit hubs. When a builder’s system is compromised, the blueprints and schematics of national defense assets can find their way onto the dark web, potentially ending up in the hands of foreign adversaries or terrorist organizations.

Dotted Line: Not if, when: How construction is dealing with cybersecurity in the age of AI

Chronology of an Escalating Threat

To understand how the construction sector arrived at this precarious juncture, it is necessary to examine how the threat landscape has evolved over recent years:

  • Pre-2020: Construction firms primarily viewed IT security through the narrow lens of basic firewall protection and occasional malware scans. Phishing attempts were crude, easily identifiable by poor grammar, and rarely targeted beyond simple financial diversion schemes.
  • 2021–2024: As the industry rapidly digitized—adopting Building Information Modeling (BIM), cloud-based project management tools, and remote work infrastructure during the pandemic—the attack surface expanded exponentially. Cybercriminals shifted toward Ransomware-as-a-Service (RaaS) models, locking up project schedules and demanding massive cryptocurrency payouts to release operational data.
  • July 2026: A critical turning point occurs as public disclosures reveal simultaneous or closely timed breaches at Turner Construction, Kiewit, and AECOM. The involvement of ITAR-protected documents thrusts construction cybersecurity into the realm of national security.
  • Present Day (2026): Artificial intelligence completely automates the threat landscape. Autonomous agent-based attacks relentlessly probe contractor networks around the clock, utilizing generative AI to craft flawless, highly targeted spear-phishing campaigns that bypass traditional human skepticism.

Supporting Data: The Disconnect Between Perception and Reality

Despite the escalating frequency and severity of these attacks, a profound disconnect persists between executive risk awareness and operational reality within the construction sector.

According to the 2026 Travelers Risk Index, U.S. businesses overall ranked cyber threats as their number one operational concern. However, when the same metric was posed exclusively to construction executives, cybersecurity languished at 10th place. Industry leaders instead prioritized traditional pain points: soaring energy costs, supply chain bottlenecks, and medical cost inflation.

Even more alarming is the pervasive sense of invulnerability among smaller and mid-sized builders. The Travelers survey revealed that 48% of all construction firms consider themselves “not big or complex enough” to be targeted by a major cyberattack.

Richard Volack, a partner at New York City-based construction law firm Peckar & Abramson and chair of the firm’s cybersecurity and data privacy practice, notes that this mindset is dangerously naive.

"Particularly for smaller companies, they might think, ‘Who am I? What do I have that they want?’" Volack explains. "You may think you have nothing that the hackers want, but you have a whole bunch."

This attitude creates a cascading vulnerability throughout the entire construction supply chain. While a multi-billion-dollar general contractor (GC) may invest heavily in enterprise-grade security, they routinely rely on dozens of specialized subcontractors, suppliers, and specialty trades.

Dotted Line: Not if, when: How construction is dealing with cybersecurity in the age of AI

Trent Cotney, a partner and construction team leader at Adams and Reese LLP in Tampa, Florida, points out that the risk profile amplifies the further down the supply chain you go. "The problem is, the more you go down the food chain, the less sophisticated contractors’ systems usually are," Cotney says. "As you become a sub, or a sub of a sub, your net revenue is less. And as a result, your risk mitigation is probably less as well."

These smaller entities often serve as the soft underbelly through which hackers gain initial network access, eventually pivoting laterally to compromise prime contractors and project owners.


Official Responses and the Emerging Weaponization of AI

When catastrophic breaches occur, the financial and operational fallout is immediate and punishing. John Menefee, vice president and enterprise cyber lead at Travelers, highlights that the true cost of an incident extends far beyond initial ransom demands.

"It’s the amount of money that you parted with and whether or not you can recover any of those funds," Menefee notes. "But it’s also the cost to investigate." For a mid-sized construction firm, forensic investigations, legal compliance, mandatory public notifications, and business interruption losses can easily scale into hundreds of thousands of dollars, if not millions.

The Business Email Compromise (BEC) Trap

One of the most insidious vectors plaguing contractors is Business Email Compromise (BEC). Cybercriminals gain unauthorized access to an accounts payable employee’s email account, monitoring transactions until they can intercept or alter routine billing cycles.

A subcontractor submits a legitimate invoice, but the hacker intercepts the communication, subtly altering the pay-to account number. If the general contractor or project owner executes a wire transfer without out-of-band verification, the funds vanish instantly.

"You have to be careful with wires, because that’s the whole idea: they move the money quickly," Volack warns. "If you’re past say 24 or 48 hours, then it’s harder, if not impossible, to put a hold on the bank."

Dotted Line: Not if, when: How construction is dealing with cybersecurity in the age of AI

AI-Powered Threats

Compounding these financial risks is the integration of artificial intelligence into the hacker’s toolkit. Cybercriminals no longer rely on manual email blasts or clumsy code.

"With AI now, it’s basically automated," Cotney explains. "Hackers can use agents to basically engage in these hostile attacks without even doing anything. They’re constantly probing and looking for potential issues."

Furthermore, generative AI has entirely eliminated the traditional red flags of phishing. Poor grammar, misspelled words, and awkward phrasing—once the hallmark indicators of a scam—have been replaced by flawless, contextually aware communications that mimic internal executives or trusted project partners. This evolution renders critical infrastructure across the construction ecosystem increasingly vulnerable.


Legal, Regulatory, and Compliance Implications

The regulatory environment surrounding data breaches has tightened considerably, exposing negligent contractors to severe legal penalties.

For projects governed by federal acquisition regulations, disclosure timelines are brutally compressed, frequently requiring mandatory reporting within 72 hours of discovering an unauthorized intrusion. Failing to meet these windows can result in swift administrative sanctions.

More ominously, contractors who suffer a breach may face legal repercussions under the False Claims Act. Federal contractors are routinely required to attest that they maintain strict, compliant cybersecurity protocols as a prerequisite for winning government work. If forensic investigations reveal that a contractor falsely certified their IT security readiness, or knowingly ignored required security baselines, they open themselves up to catastrophic whistleblower lawsuits and government fraud charges.


Hardening the Industry: A Call to "Lock Arms"

Faced with mounting financial liabilities, regulatory scrutiny, and national security pressures, legal and technological experts agree that the construction industry must fundamentally alter its defensive posture.

Dotted Line: Not if, when: How construction is dealing with cybersecurity in the age of AI

Malcolm Jack, chief technology officer at Granite Construction—a firm that proactively achieved the federal government’s rigorous Cybersecurity Maturity Model Certification (CMMC) Level 2 earlier this year—argues that the industry must treat cybersecurity with the same collaborative urgency it applies to physical jobsite safety.

"In construction, we don’t look at safety as a competitive advantage. We have Safety Week. We bond together. If there’s that new safety methodology in which we can help each other or help protect our workers, we share it," Jack says. "We need to have the same mindset for cybersecurity, that cybersecurity is not necessarily a competitive advantage. It is something we need to share with one another."

Best Practices for Mitigating Cyber Risk

Industry leaders and legal counsel recommend a multi-tiered, comprehensive framework to harden construction firms against modern cyber threats:

  1. Contractual Cascading (Waterfall Clauses): General contractors must enforce strict security requirements downward through contractual agreements. Owners mandate security protocols down to the GC, who must in turn mandate equivalent safeguards down to every tier of subcontractors and suppliers. For subs struggling to meet high-level standards, mandatory implementation of Multi-Factor Authentication (MFA) should serve as an absolute baseline requirement.
  2. Infrastructure Hardening and Penetration Testing: Contractors should regularly hire independent third-party cybersecurity firms to conduct aggressive penetration ("pen") tests, proactively identifying and patching vulnerabilities before malicious actors exploit them.
  3. Continuous Employee Training: Human error remains the single greatest vulnerability. Employees must undergo regular, recurring cybersecurity awareness training—multiple times a year—to recognize sophisticated, AI-generated phishing attempts and verify payment instructions through secure secondary channels.
  4. Strategic Insurance Review: While cyber insurance policies have become standard, contractors must engage in frank, detailed conversations with their insurance brokers. Traditional policies readily cover incident response, forensic investigations, and data restoration, but they may feature ambiguous language regarding the loss of proprietary intellectual property, engineering designs, or classified military blueprints.
  5. Demonstrating Due Diligence: "The best thing that you can do is at least be able to show your customer and the public that you took all the precautions you could possibly take," Cotney advises. "You still got breached, but you did everything you’re supposed to do."

As the construction industry marches further into the digital age, the days of hiding behind physical blueprints are over. Protecting the jobsite now requires securing the server rack just as fiercely as the perimeter fence. For contractors large and small, locking arms against the digital threat landscape is no longer just a smart business decision—it is an existential necessity.

Leave a Reply

Your email address will not be published. Required fields are marked *