Turner Construction Company, one of the largest general contractors and construction managers in the United States, has begun notifying current and former workers that an intruder sat inside its systems for roughly two weeks in July 2026 and made off with payroll-grade personal data: Social Security numbers, Canadian Social Insurance Numbers, dates of birth, salary figures, direct-deposit bank account details, home addresses and, for a smaller subset, passport numbers. The company's notification letter, dated August 18, 2026 and published by ClassAction.org, dates the unauthorized access to July 2 through July 15, 2026, with confirmation on July 27 that files containing personal information had been accessed. A filing with the California Office of the Attorney General covers 6,098 individuals; that figure is the California cohort, not a national total, and Turner has not published an overall count. The ransomware group Payouts King has claimed the intrusion and asserts it took far more than HR records.
What Happened
The timeline is consistent across every source reviewed, which is unusual and worth noting: Turner identified suspicious activity in its network, secured its systems, and brought in third-party cybersecurity and forensic experts. That investigation established a July 2 to July 15, 2026 window of unauthorized access to "certain Turner systems," and on July 27 the company confirmed that files containing personal information were among those accessed. Detailed file review followed, and written notices went out on or about August 18, 2026, the same day the California AG filing was made.
Payouts King's side of the story runs slightly ahead of Turner's. According to ClaimDEPOT, a class-action tracking site, the group first posted about an unnamed victim on July 24, 2026, then named Turner publicly on a Tor leak site on August 11, 2026, claiming 27.2 terabytes of stolen data. That sequencing puts the extortion clock roughly three weeks ahead of the individual notifications. ClaimDEPOT is the only source in this set reporting the 27.2 TB figure and the leak-site dates, and the claim originates with the threat actor. Turner has not confirmed a volume, a ransomware designation, or any encryption event, and its own statement describes only unauthorized access and an ongoing file review.
Where accounts do diverge is on scale. Construction Dive frames the California filing as "at least 6,098 individuals." Migliaccio & Rathod describes the breach as "impacting over 6,000 individuals." Class Action U and Emery Reddy both describe approximately 6,098 California residents specifically. For a firm that employs tens of thousands across North America and whose notice includes a distinct Canadian data category, the real population is almost certainly larger than the California number. Treat 6,098 as a regulatory floor.
What Was Taken
Turner's own notification letter is the authoritative list, and it is a near-complete identity kit. The categories: name, Social Security number for U.S. individuals, Social Insurance Number for Canadian individuals, date of birth, salary, bank account information used for direct deposit, and home address, with passport numbers for what the letter calls "a limited number of individuals."
That combination matters more than any single field. SSN plus date of birth plus home address is enough for synthetic identity fraud and new-account opening. Adding direct-deposit banking details enables payroll diversion and account takeover against a known institution. Adding salary gives a fraudster the income figure to make a credit application look plausible. Emery Reddy's characterization, that this is one of the more complete personal-data sets seen in a recent employer breach, is a plaintiff-side framing but not an unfair one.
Payouts King claims the haul extends well past HR. Per ClaimDEPOT's account of the group's dark web posting, the stolen set includes engineering documents containing restricted and ITAR-protected information, military project files, legal and litigation records, correspondence, financial records, contracts and non-disclosure agreements. Construction Dive independently repeats the engineering-documents, military-project-files, contracts and NDA claims, also sourced to the ClaimDEPOT post. This remains an unverified actor claim. Turner has not addressed it, and no regulator filing in this source set references defense-related material. If any part of it is accurate, particularly the ITAR assertion, the incident carries an export-control and defense-supply-chain dimension that the consumer notification process does not touch at all.
Why It Matters
Large general contractors are a soft, high-value target class that most threat models underweight. Turner sits at the center of a graph that includes owners, architects, engineering consultants, subcontractors, government clients and defense-adjacent facility work. The payroll data alone would make it worth attacking. The project data, if the actor's claims hold, makes it a route into physical infrastructure documentation for buildings that are already built and occupied.
Second, this is a payroll and HR system compromise, and the direct-deposit angle deserves specific attention. Bank account and routing details paired with employer identity are the raw material for payroll-redirect fraud, where an attacker contacts HR or self-service portals posing as the employee and changes the deposit destination. That attack is cheap, fast, and frequently succeeds before anyone notices a missed paycheck.
Third, the dwell-to-disclosure gap. Access ended July 15. Confirmation came July 27. Notification landed August 18. That is a reasonable pace by industry standards, but it means affected individuals had roughly five weeks of exposure before they could act, and the actor had named Turner publicly a week before the letters went out. Anyone whose data is in that set should assume it has been available to buyers since mid-August.
Fourth, legal exposure is already accreting. At least four plaintiff firms and class-action platforms, Cole & Van Note, Migliaccio & Rathod, Emery Reddy and ClassAction.org, opened public investigations within a day of the notices. Several of the sources in this brief are those solicitation pages, which is worth flagging as a sourcing caveat: they are accurate on the facts drawn from the notification letter and the AG filing, but they are advocacy documents, not reporting.
The Attack Technique
Initial access vector is not disclosed. Turner's notification letter says only that it "identified a cybersecurity incident involving unauthorized access to certain Turner systems." No source in this set names an exploited CVE, a phished credential, a compromised VPN or edge appliance, or a third-party vendor as the entry point. No source describes encryption of Turner systems or a ransom demand.
What can be inferred is limited but useful. A thirteen-day access window followed by a data-theft extortion posting is consistent with the modern exfiltration-first playbook: gain access, escalate, locate file shares and HR or ERP repositories, stage and exfiltrate in bulk, then extort on volume and sensitivity rather than on availability. The presence of both payroll data and, per the actor's claim, engineering and legal repositories in the same haul suggests broad file-share access rather than a single application compromise. The July 24 leak-site post for an unnamed victim, three weeks before the August 11 naming, matches the standard staged-pressure model where the victim is given a private negotiation window first.
Payouts King itself is a comparatively low-profile name. No source here provides malware families, infrastructure indicators, TTP mapping or affiliate structure, so defenders have no IOCs to hunt on from this incident. Anything published claiming otherwise should be checked hard.
What Organizations Should Do
Lock down direct-deposit change workflows. Require out-of-band verification, on a phone number of record and not one supplied in the request, for any bank account change in payroll or HR self-service. Add a mandatory notification to the employee's known-good email and a delay window before the first deposit routes to a new account. This is the single highest-yield control against the specific data lost here.
Inventory where payroll and HR files actually live. The categories in Turner's letter, SSN, SIN, DOB, salary, bank details, passport numbers, rarely stay inside the HRIS. They sprawl into file shares, finance spreadsheets, onboarding folders and email attachments. Run a discovery sweep for those field patterns outside sanctioned systems and delete or vault what you find.
Instrument for bulk egress, not just intrusion. A thirteen-day window ending in a multi-terabyte extortion claim is a detection failure on exfiltration volume. Alert on anomalous data movement to cloud storage and file-transfer services, on service accounts accessing HR shares, and on any single principal reading unusual breadth of file-share content in a short period.
Segment project and engineering repositories from corporate IT. If controlled technical data, ITAR or otherwise, lives on the same reachable file shares as HR records, one credential compromise costs you both. Enforce separate authentication domains and access review for anything under export control, and confirm your contractual obligations for reporting a suspected compromise of that data.
Extend monitoring to the contractor and joint-venture edge. Construction firms run large populations of temporary staff, JV partners and subcontractor personnel with system access. Audit dormant accounts, enforce MFA on every remote access path including partner portals, and set hard expiry on external identities.
For notified individuals: freeze credit at all three bureaus, enroll in the offered identity protection, set fraud alerts on the specific bank account used for direct deposit, and treat any unsolicited contact referencing your employer, salary or payroll as hostile. Passport-number holders should also monitor for travel-document misuse.
Sources: Turner discloses data breach of salary info, bank accounts, SSNs C... | P.O. Box 1907 Suwanee, GA 30024 <> << ... | Turner Construction Data Breach Impacts Thousands: SSNs Exposed | Turner Construction Data Breach Affects SSNs; Lawyers Investigating | Turner Construction Data Breach Lawsuit Emery Reddy | Turner Data Breach Investigation - M&R | Turner Construction Company Data Breach Lawsuit - Class Action U | Turner Construction Company Data Breach Investigation - Cole & Van...