International Edition
Latest News
Business

AECOM Data Breach: Law Firm Investigates Potential Class Action

National class action law firm Edelson Lechtzin LLP announced an investigation into data privacy claims surrounding a reported cyberattack at multinational infrastructure and engineering firm AECOM, according to a September 20, 2026 announcement published via PRNewswire. The firm…

AECOM Data Breach: Law Firm Investigates Potential Class Action

National class action law firm Edelson Lechtzin LLP announced an investigation into data privacy claims surrounding a reported cyberattack at multinational infrastructure and engineering firm AECOM, according to a September 20, 2026 announcement published via PRNewswire. The firm is offering free and confidential case evaluations for current and former employees, clients, and others whose personal information may have been exposed.

Reported Dark Web Claims and Data Breach Scope

The investigation follows claims surfacing on dark web monitoring sites regarding a cyberattack that allegedly occurred on or about September 17, 2026. According to a post on Ransomware.live cited by PRNewswire, the hacker group Metaencryptor claimed responsibility for an attack affecting approximately 1.22 terabytes of data. Separately, the cybersecurity blog HookPhish reported that Metaencryptor drove the suspected breach at the Texas-based engineering firm.

AECOM Data Breach: Law Firm Investigates Potential Class Action

In addition, dark web monitoring service Breachsense identified a related data leak listing approximately 670 gigabytes attributed to a group known as BrainCipher. Breachsense also indexed thousands of AECOM-linked credentials circulating online. These include 27,434 @aecom.com accounts drawn from external breaches and 6,077 credentials tied directly to aecom.com, featuring thousands of logins found in combo lists and infostealer malware logs with plaintext passwords. Breachsense cautioned that these credentials may belong to customers or staff and are not necessarily tied to the Metaencryptor attack. AECOM has not publicly detailed the scope or impact of the incident, and the hackers’ claims remain unconfirmed.

Potential Risks and Who Is Affected

The investigation focuses on current and former AECOM employees, clients, and any individuals whose personal data was maintained by the multibillion-dollar infrastructure consulting, engineering, design, and construction management firm. While the specific data involved remains unconfirmed, data breaches of this nature typically expose sensitive personal information, elevating risks for identity theft and financial fraud.

AECOM Data Breach: Law Firm Investigates Potential Class Action

Edelson Lechtzin LLP encourages anyone who received a data breach notification from AECOM, or who suspects their information was compromised, to step forward for a free case evaluation. Potential legal claims aim to pursue compensation for losses such as out-of-pocket costs, lost time, and loss of privacy, while pushing the firm to tighten its data protection measures.

Recommended Steps for Affected Individuals

Individuals concerned about the reported incident can take several protective measures:

  • Review financial account statements and credit reports regularly for suspicious activity.
  • Determine whether personal information was involved by monitoring communications from AECOM.
  • Preserve any letters or emails received regarding the data breach.
About the author: Marcus Liu - Business Editor

MBA and ex‑B bureau chief specializing in global finance and fintech. Marcus speaks Mandarin, Japanese, and English, and has interviewed CEOs from the Fortune 50 to Y‑Combinator unicorns. Marcus Liu delivers sharp analysis on markets, startups, and corporate strategy for investors and entrepreneurs alike.