www.dexpose.io Metaencryptor Ransomware Attack Targets AECOM
Article Content
- •AECOM suffered a ransomware attack by Metaencryptor, affecting 1.22 terabytes of data.
- •The attack was discovered on September 17, 2026, with investigations ongoing.
- •Class action lawsuits may be pursued by affected individuals against AECOM.
AECOM, a Texas-based infrastructure consulting firm, reportedly suffered a ransomware attack attributed to the hacker group Metaencryptor. The breach, which was discovered on September 17, 2026, is believed to have compromised approximately 1.22 terabytes of data. The attack was confirmed by dark web monitoring site Ransomware.live and corroborated by cybersecurity blog HookPhish. AECOM has not yet provided detailed information regarding the scope or nature of the breach. Legal investigations are underway, with attorneys seeking to file a class action lawsuit on behalf of affected individuals, including current and former employees and clients. The incident highlights the ongoing threat of ransomware attacks in 2026 and the need for enhanced cybersecurity measures. As of now, there are no known details about specific vulnerabilities exploited during the attack.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (12)
Following this threat?
Track BrainCipher and Aecom in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Ransomware Attacks Target Multiple Companies in September 2026 In September 2026, multiple ransomware groups, including Booba Project and Panzer, launched attacks on various organizations. Atlas Ocean Voyages suffered a breach where 37 GB of sensitive data was stolen, while Cerámicas Kantu S.A.C. was threatened with data release unless negotiations occurred. The attacks highlight…
Critical Zero-Day Vulnerability in F5 BIG-IP APM Exploited for Remote Code Execution F5 Networks has reported a critical vulnerability in its BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127, which is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute remote code on systems configured with both an APM access policy and an OAuth profile. This…