Construction — Cyber Threat Activity
Construction is a pure volume target, and the pattern in our log is unusually clean: more than 450 recorded incidents across 45 countries, over 180 in the trailing 180 days, and every one of the 51 attributed groups is a ransomware or extortion crew. Qilin (98), Akira (85), Play (63), DragonForce (45) and SafePay (21) lead. There is no espionage story here and the data does not pretend otherwise; zero malware families are linked to the sector through our actor graph and only 9 groups carry a profile-level research association against 51 attributed through incidents. What makes construction attractive is structural rather than strategic. Firms are asset-rich and margin-thin, project delivery is bound by contractual completion dates and liquidated damages, and the industry runs on a sprawl of subcontractors, joint ventures and shared project systems that dissolves any clean network boundary. Design documents, tender pricing and payment instructions all sit in the same accessible places, which is why construction suffers invoice and payment diversion fraud alongside encryption. Dragos placed construction at the top of its industrial ransomware subsector breakdown in early 2025, ahead of food and beverage and consumer goods, which matches what we record. Recorded geography is United States-led at 260 claims, then the United Kingdom, Canada, Australia, Germany and France. These totals are attacker claims posted to extortion sites rather than confirmed breaches. For defenders the useful conclusion is that construction is chosen for being reachable rather than for being valuable, so the controls that matter are the generic ones done properly: multi-factor authentication on remote access, patched edge devices, and offline backups of project data.
- Recorded incidents: 737
- Incidents, trailing 180 days: 213
- Tracked threat actors: 66
- Malware families: 12
Recent incidents
- Brebur 2026-08-30
- La Maison Des Travaux 2026-08-29
- lindner-group.com 2026-08-29
- AUM Construction 2026-08-29
- macallister.com 2026-08-28
- CGP MEP 2026-08-27
- Sanko Fastem (Vietnam) Co., Ltd. 2026-08-26
- Incolur 2026-08-26
- parkderochie.com 2026-08-25
- Almeer 2026-08-21
- EmpireWorks 2026-08-17
- SAGASTA sro 2026-08-16
- Lepi Enterprises 2026-08-15
- TOA 2026-08-14
- Cityside Homes 2026-08-14
- Camandona SA 2026-08-12
- AIMS Group 2026-08-10
- Zion Contracting 2026-08-10
- Cook Remodeling 2026-08-10
- Mike Graham Heating And Air Conditioning 2026-08-05
Threat actors targeting Construction
- Qilin 151 incidents
- Akira 116 incidents
- Play Ransomware 75 incidents
- DragonForce 61 incidents
- SafePay 41 incidents
- INC Ransom 32 incidents
- Lynx Ransomware 30 incidents
- LockBit 27 incidents
- The Gentlemen 26 incidents
- NightSpire 17 incidents
- Cl0p 17 incidents
- Medusa Ransomware 17 incidents
- RansomHub 13 incidents
- Sarcoma 9 incidents
- Genesis 5 incidents
- KillSec 5 incidents
- Settra 4 incidents
- RansomHouse 4 incidents
- AiLock 3 incidents
- BlackSuit 3 incidents
- Cactus 3 incidents
- Chaos 3 incidents
- Coinbase Cartel 3 incidents
- Deadlock 3 incidents
Where these victims are
- United States 355
- United Kingdom 48
- Canada 35
- Germany 31
- France 22
- Australia 16
- Switzerland 13
- Italy 12
- Singapore 10
- Austria 7
- Netherlands 7
- Czech Republic 6
Malware used against Construction
Families used by the threat actors that target this sector, derived from actor tooling rather than observed in these incidents directly.
- Cobalt Strike Malware
- Mimikatz Tool
- PsExec Tool
- Sliver Tool
- Babuk Malware
- ngrok Tool
- ProcDump Tool
- Rclone Tool
- SystemBC Malware
- ADRecon Tool
- fscan Tool
- RevSocks Tool
Coverage. 94.9% of incidents in our log carry a sector classification; the remainder name a victim we have not placed in an industry. Counts here are a floor, not a total, and are not comparable between sectors of different sizes.