Ransomware victim disclosure
← All victimsAECOM
listed as aecom.com · Claimed by BrainCipher · listed 6 hours ago
Status timeline
- ListedSep 17, 2026
- Data leakeddate unknown
At a glance
- Group
- BrainCipher
- Status
- Data leaked
- Country
- United States
- Sector
- Professional Services
- Listed on leak site
- Sep 17, 2026
About the victim
AI dossier — public-source company profileAECOM is a global infrastructure consulting and engineering firm that partners with clients across markets including cities, energy, transportation, water, healthcare, and government. They provide advisory, architecture & design, construction management, engineering, environmental, and program management services. The company operates offices worldwide and describes itself as 'the world's trusted infrastructure consulting firm.'
- Industry
- Infrastructure Consulting & Engineering
Attack summary
Severity: high — Confirmed exfiltration of a large dataset (670 GB) from a major Fortune 500 infrastructure consulting firm; infrastructure sector is critical to national security and public welfare. No specific sensitive data types disclosed yet, but the volume and sector suggest significant business/operational data at minimum.BrainCipher claims to have obtained 670 GB of data from AECOM (described as likely belonging to a Fortune 500 company) with a ransom deadline of September 25, 2026. No specific details about the nature of the exfiltrated data are provided in the post.
Original description
AI-summarised, not from the leak postAECOM is a global infrastructure and engineering firm headquartered in the United States. The company provides design, consulting, construction, and management services across sectors including transportation, water, environment, energy, and government facilities. Operating in over 150 countries, AECOM serves public and private clients worldwide and is recognized as one of the largest engineering services firms globally.
The leak post
captured from the group's siteWe've obtained 670 GB of data that most likely belongs to a Fortune 500 company. Stay tuned for more details — it's going to be interesting. If you think you are here by mistake, please contact us at [email protected] ⏳ Deadline: September 25, 2026 at 15:00
Sources
Source
Indexed 6 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

