AECOM – Data Breach Investigation
Ahdoot & Wolfson is investigating reports of a possible data breach involving AECOM, following claims that a cyberattack may have resulted in the theft of a significant amount of company data. According to reports published on September 17, 2026, the hacking group Metaencryptor claimed to have breached AECOM and allegedly obtained approximately 1.22 terabytes of data. The allegations have not been independently verified, and the full scope and nature of the reported incident remain unknown.
- Compromised Data Volume: Approximately 1.22 terabytes of data was allegedly obtained, according to claims made by the hackers. The amount and nature of the data involved have not been independently verified.
- Employee Information: The reported incident may have involved personal or employment-related information belonging to current or former AECOM employees. The specific information, if any, that may have been accessed or stolen has not yet been publicly confirmed.
- Employment Records: AECOM maintains employee records and other employment-related information, which may include payroll, benefits, employment and professional information, and other personnel records.
- Company and Project Information: The alleged attack may have involved confidential company, project, technical, contractual, or other business information. The specific categories of information allegedly accessed have not been confirmed.
- Potential Risks: If employee information was compromised, affected individuals could potentially face risks associated with unauthorized use or disclosure of their personal information.
If you are a current or former AECOM employee and believe your information may have been exposed in the reported data breach, please fill out the form below to learn more about the investigation. An attorney or legal representative may contact you to discuss the investigation and ask you a few questions.