AECOM Hit by Alleged Data Breach: Hacker Group Metaencryptor Claims 1.22TB of Stolen Data
On September 17, 2026, the hacker group Metaencryptor claimed responsibility for a suspected cyberattack on AECOM, a Texas-based multibillion-dollar infrastructure consulting firm. According to reports from dark web monitoring site Ransomware.live, the breach may have compromised 1.22 terabytes of data, with the attack allegedly occurring the same day the claim was posted.
Details about the scope and nature of the breach remain unconfirmed, including whether sensitive employee or client data was exposed. Legal teams, including those affiliated with ClassAction.org, are investigating the incident to determine if a class action lawsuit can be filed on behalf of affected individuals particularly current and former AECOM employees who believe their information may have been put at risk.
At this stage, no official statement from AECOM has been released regarding the breach. The investigation is ongoing, with attorneys seeking input from potentially impacted parties to assess damages, which could include loss of privacy, financial costs, and other harm if the breach is verified. The outcome of any legal action could also compel AECOM to strengthen its data protection measures.
Source: https://www.classaction.org/data-breach-lawsuits/aecom-september-2026
AECOM TPRM report: https://www.rankiteo.com/company/aecom
"id": "aec1789669507",
"linkid": "aecom",
"type": "Breach",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Infrastructure/Consulting',
'location': 'Texas, USA',
'name': 'AECOM',
'size': 'Multibillion-dollar',
'type': 'Infrastructure Consulting Firm'}],
'data_breach': {'data_exfiltration': '1.22TB of data allegedly stolen',
'personally_identifiable_information': 'Potentially exposed',
'sensitivity_of_data': 'Potentially sensitive employee or '
'client data'},
'date_detected': '2026-09-17',
'date_publicly_disclosed': '2026-09-17',
'description': 'On September 17, 2026, the hacker group Metaencryptor claimed '
'responsibility for a suspected cyberattack on AECOM, a '
'Texas-based multibillion-dollar infrastructure consulting '
'firm. The breach may have compromised 1.22 terabytes of data, '
'with the attack allegedly occurring the same day the claim '
'was posted. Details about the scope and nature of the breach '
'remain unconfirmed, including whether sensitive employee or '
'client data was exposed.',
'impact': {'data_compromised': '1.22TB',
'identity_theft_risk': 'Potential risk for affected individuals',
'legal_liabilities': 'Potential class action lawsuit'},
'investigation_status': 'Ongoing',
'ransomware': {'data_exfiltration': '1.22TB of data allegedly stolen'},
'references': [{'source': 'Ransomware.live'}, {'source': 'ClassAction.org'}],
'regulatory_compliance': {'legal_actions': 'Potential class action lawsuit'},
'threat_actor': 'Metaencryptor',
'title': 'AECOM Hit by Alleged Data Breach: Hacker Group Metaencryptor Claims '
'1.22TB of Stolen Data',
'type': 'Data Breach'}