Turner Told 6,098 People a Ransomware Crew Took Their Bank Details

Turner Construction started mailing breach notices on Aug. 18. The letters tell recipients that between July 2 and July 15 someone was inside Turner’s systems, and that the files they reached held Social Security numbers, dates of birth, salaries and direct-deposit bank account details. Some files also held passport numbers.

What the state filings actually say

The California Attorney General’s breach portal carries Turner’s notice, and Vermont’s lists it under an 8-18-2026 date. At least 6,098 individuals have been notified, including 38 Vermont residents. Turner confirmed on July 27 that files containing personal information had been accessed. It’s offering five years of identity protection through IDShield and IDX, with one notice setting a Nov. 18 enrollment deadline.

A ransomware group calling itself Payouts King has claimed the intrusion. It posted about an unnamed victim on July 24 and named Turner on Aug. 11 through a Tor site. The group claims it took 27.2 terabytes, including engineering documents, military project files, contracts, NDAs and ITAR-controlled material. None of that is confirmed. Turner’s statement to Construction Dive says it “engaged leading third-party cybersecurity and forensic experts to investigate” and that it “does not comment on claims made by criminal organizations.”

Why a general contractor is a target

Turner is the largest U.S. contractor by revenue and carried a $44.3 billion backlog at the end of 2025, weighted toward data centers and advanced technology work. That combination, payroll records for a very large workforce plus drawings and specifications for facilities other people care about, is a richer target than most manufacturers.

Google Threat Intelligence flagged construction-sector domains as targeted in an Aug. 6 post, which lands in the same window. Design and construction firms have historically treated cybersecurity as an IT line item rather than a project risk, and the exposure here isn’t the models or the schedules. It’s HR.

The detail worth acting on

Direct-deposit account numbers in a breach set enable payroll-diversion fraud against individual employees, and it works because the attacker already holds enough identity data to pass a help-desk check. Any firm running a workforce of comparable size should assume the same data sits in the same kind of file share, and that the share is reachable from a single compromised credential.

Treat every claim sourced to Payouts King as a criminal boast until it’s corroborated. The 27.2-terabyte figure and the ITAR assertion come from the group’s own leak site, relayed through class-action trackers now soliciting clients. The state attorney general filings are the reliable record, and they’re considerably narrower than the headlines. Turner is the victim here; no suit has been proven, and plaintiff firms posting investigation notices isn’t the same thing as litigation.

For context on the kind of work that makes a contractor’s document set valuable, see our listing for the Link Union Station run-through tracks project, where four public agencies share design documentation on a single site.

Leave a Comment