AECOM Faces Potential Data Breach Amid Hacker Claims

News related to:AECOM · 1 min read

AECOM, a U.S.-based multinational infrastructure and engineering firm, is facing a potential data breach following claims by hackers that they stole approximately 1.22 terabytes (TB) of data on or about September 17, 2026. The breach was first reported on dark web monitoring sites, raising concerns among current and former employees, clients, and anyone whose personal information may have been compromised.

According to reports, the hacker group Metaencryptor claimed responsibility for the alleged attack, which is said to have affected a significant amount of data. Separately, the dark web monitoring service Breachsense reported a related AECOM data leak of roughly 670 gigabytes (GB), attributed to a group identified as BrainCipher. Breachsense also indexed thousands of AECOM-linked credentials circulating online, including 27,434 @aecom.com accounts drawn from external breaches and 6,077 credentials tied to aecom.com itself. These credentials were found in "combo lists" and in infostealer malware logs, many with plaintext passwords, though Breachsense cautioned that these credentials may belong to either customers or staff and are not necessarily connected to the claimed attack.

In response to the potential breach, Edelson Lechtzin LLP, a national class action law firm, is offering free, confidential case evaluations to AECOM employees, clients, and others whose personal information may have been exposed. The firm encourages anyone who has received a data breach notice from AECOM or who believes their information may have been compromised to contact them for a free consultation.

The breach has not been confirmed, and important details such as the true scope of the breach, the specific data involved, and the number of people affected are not yet publicly available. AECOM has not provided further details regarding the incident.

To protect themselves, individuals are advised to regularly review their account statements and credit reports, confirm whether their information was involved in the AECOM incident, preserve any letters or emails received about the breach, and consider placing fraud alerts and enrolling in credit monitoring.

Start filing today

One press release free every week. No card required.

Create a free account