Cyber & AI intelligence
Wasteland.
Briefs indexed2597
Issues28
Published Mondays07:30 CT
█ Ransomware TURNER-CONSTRUCTIO 2026-09-11

Turner Construction: Payouts King Ransomware Data Theft

"Turner Construction, the largest general contractor in the United States, has confirmed a data breach that exposed Social Security numbers, dates of birth, salary figures, home addresses and direct-deposit bank account…"

Turner Construction, the largest general contractor in the United States, has confirmed a data breach that exposed Social Security numbers, dates of birth, salary figures, home addresses and direct-deposit bank account details belonging to current and former employees and contractors. The company's own breach filings place the intrusion window between July 2 and July 15, 2026, with internal confirmation of unauthorized file access on July 27. Notification counts differ significantly by source: Construction Dive, CySecurity News, Aliteq and Construction Industry AI all cite the California Attorney General filing figure of at least 6,098 individuals, while Bisnow reports that letters went to "more than 13,000 potentially affected individuals" across attorney general disclosures in four different states. Emery Reddy notes explicitly that Turner has not disclosed a nationwide total and that 6,098 reflects California residents only. The ransomware group Payouts King has claimed responsibility and says it holds 27.2 terabytes of Turner data, a claim Turner will not address.

What Happened

The timeline across sources is broadly consistent. Turner determined that an unauthorized party had access to its systems from July 2 to July 15, 2026, a window of roughly two weeks. On July 27, the company confirmed that files containing personal information had been accessed without authorization. Turner reported the incident to the California Attorney General on August 18, 2026, per both Construction Industry AI's reading of the breach register and Emery Reddy's citation of the same filing.

Notification dates are where accounts diverge. Emery Reddy states Turner "began notifying approximately 6,098 California residents around that same date" of August 18. Construction Dive reported on August 21 that Turner had notified individuals "on Tuesday," and Aliteq's timeline places written notices on August 21, roughly seven weeks after the intrusion began. Bisnow, publishing August 24, describes the letters as having gone out on August 18 to more than 13,000 people across four states. The most likely reconciliation is a staggered rollout of state-by-state filings and mailings across that week, but no source confirms that directly, and the discrepancy in headcount between 6,098 and 13,000-plus is not resolved by any of the available reporting.

Payouts King's disclosure followed its own schedule. Per ClaimDEPOT's account, relayed by CySecurity News and Construction Dive, the group first posted about an unidentified victim on July 24, then publicly named Turner on August 11 via a Tor-hosted leak site. Note that Bisnow refers to the group as "Payout Kings," a variant spelling not used by any other source; the majority rendering across reporting is Payouts King.

Turner's public statement has been identical across outlets: the company engaged third-party cybersecurity and forensic experts, those experts continue reviewing the files involved, individuals are being notified, complimentary identity protection is being provided, and "Turner does not comment on claims made by criminal organizations." Construction Industry AI reports the identity protection offer is five years through IDShield and IDX, with an enrollment deadline of November 18.

What Was Taken

Two categories of claim need to be kept separate here, and most of the coverage does keep them separate.

Confirmed by Turner's own notice. Names, Social Security numbers, dates of birth, salary information, bank account information used for direct deposit, and home addresses. A limited subset of individuals also had passport numbers exposed. Emery Reddy adds a detail absent from the other accounts, drawn from Turner's Notice of Privacy Incident: the exposure includes Social Insurance Numbers for Canadian personnel alongside SSNs for US personnel, reflecting Turner's cross-border workforce. Construction Industry AI reports at least 38 Vermont residents notified in addition to the California count.

Claimed by the threat actor, not confirmed by Turner. Payouts King claims 27.2 terabytes of data extending far beyond HR records, specifically engineering documents containing employee personal data, military project files, legal and litigation records, correspondence, financial records, contracts and non-disclosure agreements. ClaimDEPOT, the class-action tracking site that first surfaced the leak-site post, reports that some of the material is restricted under the International Traffic in Arms Regulations. Aliteq is direct about the epistemic status: Turner has confirmed the personal-data theft, has not confirmed the military-files claim, and independent verification does not exist. Treat the 27.2TB figure and the ITAR characterization as actor claims sourced through a single reporting chain (ClaimDEPOT, reproduced by the outlets above), not as established fact.

Why It Matters

The payroll exposure alone is close to a worst case for identity fraud. SSN plus date of birth plus home address plus direct-deposit bank account details is a complete enough set to support both new-account fraud and payroll-diversion attacks against the individuals named. The addition of passport numbers for a subset raises the ceiling further. Emery Reddy characterizes it as "one of the most complete personal-data sets seen in a recent employer breach," and on the record as described that is a fair reading.

The strategic concern sits with the unconfirmed half. Bisnow reports Turner holds $2.8B in government awards and a major multiyear contract for the Arnold Engineering Development Complex at Arnold Air Force Base. Construction Industry AI places Turner first on ENR's 2026 Top 400 with $28.3 billion in 2025 revenue. Aliteq's framing is the one defenders should sit with: large construction management firms end up on hospital builds, semiconductor fabs and government facilities precisely because they can handle cleared work, which means their document repositories accumulate technical data that is legally required to stay inside US borders and away from foreign nationals. If Payouts King's characterization is accurate, the regulatory and national-security exposure runs well past breach-notification law. If it is inflated, it is still a reminder that the contractor tier holds the drawings even when the owner holds the clearance.

There is also a governance dimension. MitchelLake's leadership wire frames the incident as a board-level event rather than a technical one, arguing the tell is whether the response produces senior accountability in security, risk and data governance reporting high enough to change decisions, versus a contractor engagement. That is a useful signal to watch for any peer firm reading this.

Litigation has already begun to assemble. ClassAction.org and Emery Reddy are both soliciting affected individuals for class-action investigations as of August 19.

The Attack Technique

No source in this set describes an initial access vector, an exploited CVE, a malware family, or a specific intrusion technique. Turner has not disclosed how the attacker got in, and no vendor advisory or CERT bulletin covering this incident appears in the available reporting. Anyone stating a root cause for this breach right now is speculating.

What the public record does support is a shape rather than a mechanism. The observable pattern is a two-week dwell window ending July 15, followed by a leak-site teaser on July 24 and a named post on August 11, with the actor advertising volume (27.2TB) rather than encryption impact. No source describes systems being encrypted or operations being disrupted. That profile is consistent with exfiltration-first extortion, where data theft and public naming are the leverage and the encryption stage is either secondary or skipped, and it suggests staging and bulk egress of file shares over a period of days went undetected. Payouts King itself is not a group with established public profiling in these sources; treat it as a low-confidence attribution beyond its own self-claim.

What Organizations Should Do

  1. Instrument for bulk egress, not just encryption. A 27.2TB claim, if anywhere near accurate, implies sustained outbound transfer over days. Baseline normal data movement from file servers, document management systems and engineering repositories, then alert on volume and destination anomalies. Detection that keys on ransomware encryption behavior will miss this entire class of incident.

  2. Locate and segment your export-controlled and contractual document stores. For construction, engineering and defense-adjacent firms specifically: know which repositories hold ITAR or CUI-scoped technical data, enforce access controls and geographic restrictions on them independently of general corporate file access, and log every read at that tier. The lesson of this incident is that HR data and project drawings sat close enough together to be taken in the same operation.

  3. Harden payroll and direct-deposit change workflows now. Every employee whose bank details, SSN and date of birth are in an attacker's hands is a candidate for payroll-diversion social engineering. Require out-of-band verification for direct-deposit changes, and assume the caller can answer knowledge-based questions correctly.

  4. Compress the confirm-to-notify gap. Turner's July 27 internal confirmation preceded regulator filing on August 18 and notification in the days after, roughly three weeks. Pre-build the notification machinery (counsel, forensics retainer, state-by-state filing templates, identity protection vendor) so forensic review is the only variable.

  5. Extend the scope of your notification math to non-US personnel. Turner's notice covered Canadian Social Insurance Numbers alongside US SSNs. Multinational workforces generate multi-jurisdictional obligations that a California-first response process will not surface on its own.

  6. Decide your public posture on actor claims in advance. Turner's "we do not comment on claims made by criminal organizations" is defensible, but it leaves the most consequential allegation (military and ITAR files) unanswered in public for weeks. Agree with counsel, ahead of an incident, on what you will and will not confirm, and on the threshold at which regulators and contracting officers get told directly regardless of the public line.

Sources: Turner Discloses Data Breach Exposing Salary Info, Bank Accounts, a... | Turner discloses data breach of salary info, bank accounts, SSNs | Turner Construction Data Breach 2026: 6,098 Notified, SSNs & ITAR F... | Turner Construction Hit With Cyberattack, Hackers Claim Leaks Of Mi... | Someone Stole a Payroll File From America's Largest Contractor. The... | Turner Construction Company — Cybersecurity Incident - MitchelLake | Turner Construction Data Breach Affects SSNs; Lawyers Investigating | Turner Construction Data Breach Lawsuit Emery Reddy