The reported breach surfaced on September 17, 2026, when dark web monitoring sites identified claims from the group Metaencryptor regarding a 1.22 TB data theft. A secondary report from the service Breachsense pointed to a separate 670 GB leak attributed to a group known as BrainCipher. Beyond these specific claims, researchers identified thousands of AECOM-linked credentials—including over 27,000 email accounts—circulating in external databases and malware logs, some containing plaintext passwords.
Although AECOM has not publicly validated the scope or the authenticity of these claims, the potential exposure threatens current and former employees, along with the firm’s clients. Edelson Lechtzin LLP is currently offering confidential evaluations to individuals who believe their data may have been compromised. The firm’s investigation aims to determine if legal remedies are warranted for the potential loss of privacy and associated risks of identity theft, urging those who receive official breach notifications to secure their accounts and monitor credit reports immediately.

Comments (0)
No comments yet. Be the first!