Ransomware victim disclosure
← All victimsAECOM
Claimed by Metaencryptor · listed 5 hours ago
Status timeline
- ListedSep 17, 2026
- Data leakeddate unknown
At a glance
- Group
- Metaencryptor
- Status
- Data leaked
- Country
- United States
- Sector
- Professional Services
- Listed on leak site
- Sep 17, 2026
About the victim
AI dossier — public-source company profileAECOM is a leading global infrastructure consulting and engineering company providing design, engineering, construction management, and advisory services. They serve public and private-sector clients across transportation, water, energy, buildings, environmental services, and government markets with operations worldwide.
- Industry
- Infrastructure Consulting & Engineering
Attack summary
Severity: medium — Claimed compromise of a major infrastructure consulting firm with potential access to sensitive client project data, but no files published yet and no operational disruption confirmed. Severity elevated from 'low' due to the critical nature of infrastructure sector and likelihood of sensitive project information, but without proof publication remains unconfirmed.The metaencryptor group claims to have compromised AECOM but states that files for this campaign have not been published yet, indicating data exfiltration without current proof disclosure.
What the group claims
AECOM is a leading U.S.-based global infrastructure consulting and engineering company. It provides design, engineering, construction management, and advisory services for major infrastructure projects across transportation, water, energy, buildings, environmental services, and government markets. AECOM operates worldwide and serves public- and private-sector clients.
The leak post
captured from the group's siteAECOM is a leading U.S.-based global infrastructure consulting and engineering company. It provides design, engineering, construction management, and advisory services for major infrastructure projects across transportation, water, energy, buildings, environmental services, and government markets. AECOM operates worldwide and serves public- and private-sector clients. Files for this campaign have not been published yet.
Sources
Source
Indexed 5 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

