This feature is part of “The Dotted Line” series, which takes an in-depth look at the complex legal landscape of the construction industry. To view the entire series, click here.
There’s an accepted aphorism in the cybersecurity space: It’s not if your systems will be breached, it’s when.
That “when” came for three leading construction contractors recently. Turner Construction, Kiewit and AECOM have all garnered attention since July for reportedly unauthorized access into their systems, according to public notices and lawsuits.
In the case of Turner, the breach may have compromised social security numbers, bank accounts and passport information. Bad actors may have also accessed sensitive government data.
A hacker group called Payouts King claimed it had accessed documents in Turner’s system protected by International Traffic in Arms Regulations, a set of U.S. government rules covering the export and import of military items. In a statement to Construction Dive at the time, Turner declined to address the assertion, saying it “does not comment on claims made by criminal organizations.”
Construction lawyers say the incidents illustrate why cybersecurity attacks in 2026 are different in the construction sector. Namely, the major contractors building government projects across the U.S. house not only personal information within their tech stacks, but also what amounts to state secrets.

“If you’re a contractor working in the governmental sector, particularly for the Department of Defense, you will be introduced to plans and specifications for governmental and or military installations,” said Richard Volack, a partner at New York City-based construction law firm Peckar & Abramson who chairs the firm’s cyber security and data privacy practice. “If that information were to get out, it would be worth a lot of money on the black market, particularly to terrorists, non-governmental actors or foreign governments hostile to the U.S.”
Construction’s blasé attitude
Although that possibility is alarming in itself, these breaches are also happening in an industry that to date has been somewhat blasé on the cybersecurity front.
U.S. businesses ranked cyber threats as the top overall concern in 2026, according to insurer Travelers. Among construction companies, however, those issues ranked just 10th. The 2026 Travelers Risk Index found construction execs’ cybersecurity worries landed behind other concerns such as energy costs, supply chain and medical cost inflation, according to details of the report shared with Construction Dive. Moreover, 48% of all construction firms surveyed said they consider themselves not big or complex enough to be the victim of a major cyber-attack.
That can be a typical attitude among contractors, Volack said.
“Particularly for smaller companies, they might think, ‘Who am I? What do I have that they want?’” Volack said. “You may think you have nothing that the hackers want, but you have a whole bunch.”
Indeed, small shops are often the weakest link in the cyber chain, attorneys say, especially when they’re doing work for prime contractors with billions of dollars in revenue.

“The problem is, the more you go down the food chain, the less sophisticated” contractors’ systems usually are, said Trent Cotney, partner and construction team leader in the Tampa, Florida, office of law firm Adams & Reese. “As you become a sub, or a sub of a sub, your net revenue is less. And as a result, your risk mitigation is probably less as well.”
Email scams
That’s particularly true when it comes to business email compromise scams, where hackers take control of a particular user’s account, such as accounts payable, and send out invoices on their behalf.
For a contractor down the chain, the email and invoice may look like a routine request for payment from a known sender, with the one difference being the pay-to account number. If a fraudulent payment is made to the bad actor via wire, for example, things can go south fast.
“You have to be careful with wires, because that's the whole idea: they move the money quickly,” Volack said. “If you’re past say 24 or 48 hours, then it’s harder, if not impossible, to put a hold on the bank.”
Beyond the lost funds, the costs of a breach can grow exponentially, particularly when notification, compliance, legal and forensics costs are taken into account.

“It's the amount of money that you parted with and whether or not you can recover any of those funds,” John Menefee, vice president and enterprise cyber lead at Travelers, told Construction Dive. “But it's also the cost to investigate.”
For a mid-sized company, “we have claims where those costs can be upwards of hundreds of thousands” of dollars, Menefee said.
Artificial intelligence and cybersecurity
All of these concerns have only been exacerbated by the surging growth of artificial intelligence, which has helped cybercriminals accelerate attempts to gain unauthorized access to systems.
“With AI now, it’s basically automated,” Cotney said. “Hackers can use agents to basically engage in these hostile attacks without even doing anything. They're constantly probing and looking for potential issues.”
Unlike phishing emails in the past, lawyers say, the grammar is often perfect, since it’s written by generative AI and harder for a worker to flag. The result is that “it makes all of our critical infrastructure potentially vulnerable,” according to Cotney.
There are also liability and business risks baked into a breach. State-level disclosure rules typically require companies to report when individuals’ personal information is compromised — hence the disclosure letters that come in the mail. For government contractors operating under federal acquisition regulations, timelines are often compressed to require notification within 72 hours of discovery, Cotney said.
And if contractors’ cybersecurity efforts are determined to be below par after the fact, a breach could bring about False Claims Act consequences.
“It's potentially something that could manifest if you attested to the fact that you had the required cybersecurity protocols in place in advance and you did not,” Cotney said.
Hardening against cyber risks
The bottom line is that in 2026, cybersecurity risk is becoming an ever more serious and extensive issue for contractors, lawyers say.
That’s why the industry needs to “lock arms” around cybersecurity, as it has with physical safety in the past, said Malcolm Jack, chief technology officer at Watsonville, California-based Granite Construction, which achieved the federal government's Cybersecurity Maturity Model Certification Level 2 earlier this year.

“In construction, we don’t look at safety as a competitive advantage. We have Safety Week. We bond together. If there's that new safety methodology in which we can help each other or help protect our workers, we share it,” Jack said. “We need to have the same mindset for cybersecurity, that cybersecurity is not necessarily a competitive advantage. It is something we need to share with one another.”
Lawyers advise a tiered approach. That includes writing protections into the contract, hiring outside firms to harden existing IT infrastructure with penetration or “pen” tests of your system, purchasing a cybersecurity insurance policy to help cover losses when they occur and, perhaps most importantly, putting regular training in place for employees to recognize and avoid attacks.
“Train your people,” Volack said. “Train them multiple times a year.”
From a contract standpoint attorneys advise to have waterfall clauses that apply to subs to mandate that they also have systems and protocols in place.
“Most owners will have security protocols and then they'll fold them down to the GC,” Volack said. “Then they'll ask that the GC fold the security protocols down to the subs.”
When subs have trouble meeting a minimum threshold, Volack advises for a requirement to at least have multifactor authentication, where password-protected systems prompt entry of a one-time code for access.
“The subs need at least a smaller version of the cybersecurity and maturity model,” he said.
On the insurance front, though cybersecurity policies have become more common in business, Cotney cautioned contractors to have a frank conversation with their insurance agents. Those policies usually cover incident response, investigating what happens and data restoration.
“But where it gets a little bit more complicated is let's say you lose military plans or you lose engineering drawings or you lose something like that,” Cotney said. “Does that cyber policy cover that? And that's where it doesn't necessarily fit into typical policy language.”
For Cotney, taking all of those steps is a path forward toward recovery when the inevitable eventually does happen.
“The best thing that you can do is at least be able to show your customer and the public that you took all the precautions you could possibly take,” Cotney said. “You still got breached, but you did everything you're supposed to do.”