AECOM Data Breach Investigation: Edelson Lechtzin LLP Probes Class Action Claims After Hackers Allege Theft of More Than 1 TB of Data

aecom-data-breach-investigation:-edelson-lechtzin-llp-probes-class-action-claims-after-hackers-allege-theft-of-more-than-1-tb-of-data
AECOM Data Breach Investigation: Edelson Lechtzin LLP Probes Class Action Claims After Hackers Allege Theft of More Than 1 TB of Data

National class action law firm offers free, confidential case evaluations to AECOM employees, clients, and others whose personal information may have been exposed in the reported AECOM data breach.

, /PRNewswire/ — Edelson Lechtzin LLP, a national class action law firm, is investigating data privacy claims arising from a reported data breach at AECOM, the U.S.-based multinational infrastructure and engineering firm. Anyone who has received a data breach notice from AECOM, or who believes their personal information may have been exposed, can request a free case evaluation.

AECOM data breach — at a glance:

  • Company: AECOM, a Texas-based, multibillion-dollar multinational infrastructure consulting, engineering, design, and construction management firm.
  • Reported: A cyberattack said to have occurred on or about September 17, 2026, first surfaced on dark web monitoring sites.
  • Hackers’ claims: The group Metaencryptor claimed responsibility for an attack said to involve approximately 1.22 terabytes (TB) of data. Separately, dark web monitoring service Breachsense listed a related AECOM leak of roughly 670GB attributed to a group identified as BrainCipher.
  • Status: The breach and the hackers’ claims remain unconfirmed. AECOM has not publicly detailed the scope or impact.
  • Who may be affected: Current and former AECOM employees, clients, and others whose data AECOM held.
  • Cost to you: Nothing. Case evaluations are free and confidential.

What Happened

According to a September 17, 2026 post on the dark web monitoring site Ransomware.live, the hacker group Metaencryptor claimed responsibility for a cyberattack on AECOM that allegedly affected about 1.22 TB of data. The cybersecurity blog HookPhish similarly reported that Metaencryptor was behind a suspected attack on the engineering firm.

Separately, the dark web monitoring service Breachsense reported an AECOM data leak listed at approximately 670GB, attributed to a group it identified as BrainCipher. Breachsense also indexed thousands of AECOM-linked credentials circulating online, including 27,434 @aecom.com accounts drawn from external breaches and 6,077 credentials tied to aecom.com itself — among them thousands of logins found in “combo lists” and in infostealer malware logs, many with plaintext passwords. Breachsense cautioned that those credentials may belong to either customers or staff and are not necessarily connected to the claimed attack.

The breach has not been confirmed, and important details (including its true scope, the specific data involved, and the number of people affected) are not yet publicly available.

What Personal Information May Be at Risk

The specific data involved in the reported AECOM data breach has not been confirmed. Data breaches like this can expose personal information, increasing the risk of identity theft and fraud. Affected individuals should treat any AECOM breach notification seriously.

Who May Be Affected by the AECOM Data Breach

The investigation focuses on current and former AECOM employees, clients, and anyone else whose personal information AECOM maintained. Anyone who has received a data breach notification from AECOM may face an increased risk of identity theft and fraud and is encouraged to come forward.

Your Legal Options

Edelson Lechtzin LLP is investigating a potential class action to pursue legal remedies on behalf of individuals whose sensitive personal data may have been compromised in the reported AECOM breach. A successful case could recover compensation for losses such as lost time, out-of-pocket costs, and loss of privacy, and could push AECOM to strengthen how it protects personal information. The firm will evaluate your rights and potential claims at no cost.

Recommended Steps to Protect Yourself

  • Review your account statements and credit reports regularly and stay alert for suspicious activity.
  • Confirm whether your information was involved in the AECOM incident.
  • Preserve any letters or emails you received about the breach.
  • Consider placing fraud alerts and enrolling in credit monitoring.

Contact Us for a Free Case Evaluation

Speak confidentially with a data privacy attorney today: Marc Edelson, Esq., Edelson Lechtzin LLP, 411 S. State Street, Suite N-300, Newtown, PA 18940; Phone: 844-696-7492; Email: [email protected]; Web: www.edelson-law.com. Or click HERE to request a free consultation.

About Edelson Lechtzin LLP

Edelson Lechtzin LLP is a national class action law firm with offices in Pennsylvania and California. In addition to data breach litigation, the firm handles class and collective actions involving securities and investment fraud, federal antitrust violations, ERISA employee benefit plans, wage theft, and consumer fraud.

Media and Partnership Inquiries: Use the contact information above to connect with our team regarding interviews, co-counsel opportunities, and referral partnerships.

Legal Notice: This press release may be considered Attorney Advertising in some jurisdictions. Prior results do not guarantee a similar outcome. The reported data breach and the hackers’ claims described above are unconfirmed.

SOURCE Edelson Lechtzin LLP