Turner Construction data breach (Payout Kings)
Turner Construction disclosed that attackers accessed its network in July 2026 and stole Social Security numbers, bank account details and passport numbers, with the Payout Kings extortion group claiming to have exfiltrated some 27 terabytes of data including sensitive project files.
- Victim
- Turner Construction Company
- users
- 13.0K
On 18 August 2026, Turner Construction Company β one of the largest general builders and construction managers in the United States β began notifying more than 13,000 individuals that attackers had accessed its network and stolen sensitive personal data. The intrusion took place between 2 and 15 July 2026, and the exposed information includes Social Security numbers, bank account information and passport numbers.
The extortion group Payout Kings claimed responsibility on its dark-web leak site, saying it had exfiltrated roughly 27.2 terabytes of data from Turner. According to the group's post, the haul included engineering documents containing employees' personal data, military project files, legal and litigation records, correspondence, financial records, contracts and non-disclosure agreements.
What happened
Turner disclosed the breach through state attorney-general filings and individual notification letters, initially reporting several thousand affected residents across states including California and Vermont, with the broader count exceeding 13,000 individuals. The company said the compromised data set contained highly sensitive identifiers β Social Security numbers, financial account details and passport numbers β and offered affected individuals identity-protection services at no cost for five years through IDShield and IDX.
The scale of the claimed theft, and the sensitivity of a builder's project archive, made the incident notable beyond the personal-data exposure. Construction firms handle drawings, contracts and correspondence for critical and sometimes classified facilities, so the reported presence of military project files and NDAs raised concerns extending past the individuals directly notified.
Impact
- Personal data β Social Security numbers, bank account details and passport numbers β for more than 13,000 individuals was exposed.
- Payout Kings claims to have stolen roughly 27.2 TB of data, reportedly including sensitive engineering, legal and military project material.
- Affected individuals face elevated identity-theft and financial-fraud risk; Turner offered five years of identity protection.
Why it matters
The Turner breach shows why large construction and engineering firms are increasingly attractive ransomware and extortion targets: they aggregate not only employee and partner personal data but also project documentation for infrastructure, corporate and government clients. When a single intrusion sweeps up drawings, contracts and correspondence alongside Social Security and passport numbers, the damage spans both individual identity fraud and potential exposure of sensitive facility information β a combination that makes payment pressure and downstream risk unusually acute.
Timeline
Attackers begin accessing Turner Construction's network.
The intrusion window ends; the attackers have exfiltrated large volumes of data.
Turner confirms the breach in notification letters to more than 13,000 individuals and files with state attorneys general.
The Payout Kings extortion group claims responsibility, saying it obtained roughly 27.2 TB of data.
Sources
- constructiondive.comhttps://www.constructiondive.com/news/turner-construction-data-breach-ssns-bank-accounts/828454/
- bisnow.comhttps://www.bisnow.com/news/national/construction-development/turner-construction-data-breach-may-include-military-files-ndas
- teiss.co.ukhttps://www.teiss.co.uk/news/major-us-construction-company-discloses-data-breach-affecting-customer-data-18049