The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Construction

Breach intelligence, attack campaigns, and threat reports targeting the Construction sector.

33 threat reports
Page 1 of 3

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Construction Threat Reports

Showing 1–12 / 33 reports
EvilTokens Exposed: How Storm-2992's AI-Powered PhaaS Bypassed MFA at Scale
Impact· HIGH

EvilTokens Exposed: How Storm-2992's AI-Powered PhaaS Bypassed MFA at Scale

EvilTokens emerged in February 2026 as a sophisticated phishing-as-a-service (PhaaS) platform operated by threat actor Storm-2992, compromising over 12,000 inboxes across 10,000+ organizations worldwide. The platform exploited OAuth device code authentication flows through AI-powered phishing campaigns, enabling cybercriminals to bypass multifactor authentication and steal authentication tokens at scale. EvilTokens featured 44 customizable phishing templates, automated AI assistants for crafting targeted lures, and multi-stage delivery pipelines designed to evade traditional email security controls. This incident highlights the industrialization of token-based attacks as organizations increasingly adopt MFA, forcing threat actors to evolve beyond credential theft toward authentication bypass techniques that exploit legitimate OAuth flows and cloud service integrations.

2 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
EvilTokens PhaaS Platform Disrupted After Compromising 12,000 Microsoft Accounts
Impact· HIGH

EvilTokens PhaaS Platform Disrupted After Compromising 12,000 Microsoft Accounts

In September 2026, Microsoft's Digital Crimes Unit successfully disrupted the EvilTokens phishing-as-a-service platform that had compromised over 12,000 Microsoft accounts across 10,000+ organizations since February 2026. The platform specialized in device-code phishing attacks that bypassed multi-factor authentication by abusing OAuth 2.0 device authorization flows, targeting wholesale distribution, construction, financial services, healthcare, and education sectors. Two suspected administrators were arrested in the UK, though the threat remains active with affiliates creating clone platforms. This incident highlights the escalating sophistication of phishing-as-a-service operations and the growing threat of device-code authentication abuse, which has seen a 37x surge in attacks as cybercriminals adopt AI-powered tools for enhanced targeting and evasion.

2 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
EvilTokens Takedown: How AI Transformed Phishing-as-a-Service in 2026
Impact· HIGH

EvilTokens Takedown: How AI Transformed Phishing-as-a-Service in 2026

In September 2026, Microsoft coordinated a global takedown of EvilTokens, a sophisticated phishing-as-a-service platform that leveraged artificial intelligence throughout its attack chain. The Storm-2992 threat group operated this commercial cybercrime service, which exploited OAuth 2.0 device authorization flows to compromise over 12,000 email inboxes across 10,000 organizations worldwide. EvilTokens featured an AI-powered chatbot that analyzed victim inboxes to identify trusted relationships and recommend fraud strategies, significantly lowering the technical barriers for business email compromise attacks. The platform generated approximately $1.1 million in revenue and targeted organizations across wholesale distribution, construction, financial services, healthcare, and education sectors. This incident highlights the dangerous convergence of AI technology with cybercrime infrastructure, demonstrating how threat actors are weaponizing artificial intelligence to automate and scale sophisticated social engineering attacks at an unprecedented level.

2 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
PREY-0058: How Vishing Attacks Are Bypassing Microsoft 365 Security
Impact· HIGH

PREY-0058: How Vishing Attacks Are Bypassing Microsoft 365 Security

Arctic Wolf identified PREY-0058, a widespread data theft and extortion campaign targeting Microsoft 365 and SaaS platforms through sophisticated vishing attacks. The threat actors impersonate IT help desk personnel, directing executives to fraudulent authentication pages that harvest credentials and MFA tokens via adversary-in-the-middle techniques. Using residential proxy infrastructure like NodeMaven, attackers perform session replay attacks to access SharePoint, OneDrive, Exchange, and Box for mass data exfiltration before issuing extortion demands. The campaign primarily targets directors and executives across construction, healthcare, finance, and professional services sectors. This incident highlights the growing sophistication of identity-based attacks that bypass traditional security controls. As organizations increasingly rely on cloud services and remote access, vishing campaigns exploiting human factors and legitimate authentication flows represent a critical threat vector requiring enhanced user education and phishing-resistant authentication measures.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Industrial Automation Under Siege: Q2 2026 Threat Landscape Analysis
Impact· HIGH

Industrial Automation Under Siege: Q2 2026 Threat Landscape Analysis

In Q2 2026, Kaspersky's industrial threat landscape report revealed a significant shift in cybersecurity threats targeting industrial control systems (ICS), with malicious objects blocked on 19.15% of ICS computers—the lowest level since 2022. The report identified 10,904 different malware families affecting industrial automation systems, with malicious scripts and phishing pages leading threat categories at 5.42% globally. Notable regional variations emerged, with Africa showing the highest attack rates at 27.9% while Northern Europe recorded the lowest at 8.1%. The biometrics sector faced the most severe threats at 26.44%, experiencing increases across multiple threat vectors including ransomware, spyware, and malicious documents. This trend reflects the evolving sophistication of threat actors targeting critical infrastructure, coinciding with increased adoption of cloud-native industrial systems and the expansion of attack surfaces through IoT integration. The data highlights growing concerns around industrial cybersecurity as nation-state actors and cybercriminal groups increasingly focus on operational technology environments.

4 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Bearlyfy's Custom GenieLocker Ransomware: A New Threat to Russian Enterprises
Impact· HIGH

Bearlyfy's Custom GenieLocker Ransomware: A New Threat to Russian Enterprises

In March 2026, the pro-Ukrainian hacking group Bearlyfy, also known as Labubu, launched over 70 cyberattacks against Russian companies, primarily targeting the manufacturing sector. The group deployed a custom-built Windows ransomware strain named GenieLocker, marking a significant evolution from their previous use of third-party encryptors like LockBit 3 and Babuk. These attacks involved exploiting external services and vulnerable applications to gain access, followed by the deployment of tools such as MeshAgent for remote access and encryption. Ransom demands escalated to hundreds of thousands of dollars, with approximately 20% of victims reportedly paying. ([thehackernews.com](https://thehackernews.com/2026/03/bearlyfy-hits-70-russian-firms-with.html?utm_source=openai)) This incident underscores the increasing sophistication and boldness of hacktivist groups in leveraging custom malware to achieve both financial gain and strategic sabotage. The development and deployment of proprietary ransomware like GenieLocker highlight a trend where threat actors are investing in bespoke tools to enhance their operational effectiveness and evade detection. ([thehackernews.com](https://thehackernews.com/2026/03/bearlyfy-hits-70-russian-firms-with.html?utm_source=openai))

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Vulnerabilities Discovered in Johnson Controls' C-CURE 9000 and Victor Application Servers
Impact· HIGH

Critical Vulnerabilities Discovered in Johnson Controls' C-CURE 9000 and Victor Application Servers

In July 2026, multiple critical vulnerabilities were identified in Johnson Controls' C-CURE 9000 and Victor application servers, widely used in physical security management. These vulnerabilities, including CVE-2026-21655, CVE-2026-21653, and CVE-2026-34496, could allow unauthenticated attackers to execute arbitrary code, perform server-side request forgery, and escalate privileges, potentially compromising physical security systems and sensitive data. ([johnsoncontrols.com](https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories?utm_source=openai)) The discovery of these vulnerabilities underscores the increasing targeting of critical infrastructure by cyber threats. Organizations must prioritize patching and implementing robust security measures to protect against such exploits, as the exploitation of these flaws could lead to significant operational disruptions and security breaches.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Ransomware Surge in 2026: Understanding the 25% Increase and Its Implications
Impact· CRITICAL

Ransomware Surge in 2026: Understanding the 25% Increase and Its Implications

Between April 2025 and March 2026, ransomware incidents surged by 25%, with 7,551 known victims worldwide. This escalation was driven by the emergence of over 60 new ransomware groups and a significant increase in attacks targeting small and medium-sized businesses (SMBs). Notably, the Qilin ransomware group experienced a 443% year-over-year increase in activity, operating across more than 50 countries. The manufacturing sector remained the top target, accounting for 1,660 victims. ([gbhackers.com](https://gbhackers.com/2026-ransomware-report/?utm_source=openai)) This trend underscores the evolving threat landscape, where ransomware groups are becoming more operationalized, and the barriers to entry are lowering. Organizations must enhance their cybersecurity measures, focusing on patching known vulnerabilities, strengthening vendor oversight, and preparing for AI-driven threats. ([mbtmag.com](https://www.mbtmag.com/cybersecurity/news/22970998/report-addresses-evolving-state-of-ransomware?utm_source=openai))

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
FBI Issues Warning on Fake Permit Fee Phishing Scam
Impact· MEDIUM

FBI Issues Warning on Fake Permit Fee Phishing Scam

In March 2026, the FBI issued a public alert regarding a sophisticated phishing campaign where cybercriminals impersonated city and county planning officials to defraud property owners. By leveraging publicly accessible permit records, these actors sent emails to individuals with active applications, demanding payments for fictitious permit fees via wire transfers, peer-to-peer transfers, or cryptocurrency. The emails were meticulously crafted, incorporating real permit details to enhance credibility, leading victims to authorize payments that bypassed traditional fraud detection mechanisms. This scheme resulted in significant financial losses and highlighted vulnerabilities in existing payment verification processes. The urgency of this issue is underscored by the rapid escalation of government impersonation scams, which nearly doubled in reported losses to approximately $798 million in 2025. The increasing sophistication of these attacks, particularly their ability to exploit publicly available data and evade standard fraud detection systems, necessitates immediate attention and the development of more robust security measures to protect individuals and businesses from such fraudulent activities.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Iranian Hackers Target U.S. Industrial Control Systems in 2026
Impact· HIGH

Iranian Hackers Target U.S. Industrial Control Systems in 2026

In early 2026, Iranian state-sponsored hackers launched a series of cyberattacks targeting U.S. critical infrastructure, focusing on industrial control systems (ICS) such as Rockwell Automation's Allen-Bradley programmable logic controllers (PLCs). These attacks exploited vulnerabilities in internet-exposed devices, leading to operational disruptions and potential safety hazards across sectors like water treatment and energy. ([nextgov.com](https://www.nextgov.com/cybersecurity/2026/04/pro-iran-hackers-are-targeting-us-industrial-control-systems-advisory-says/412679/?oref=ng-homepage-river&utm_source=openai)) This incident underscores the escalating threat landscape for ICS environments, highlighting the urgent need for organizations to secure operational technology assets against sophisticated nation-state actors. ([cybersecuritydive.com](https://www.cybersecuritydive.com/news/critical-infrastucture-plcs-iran-hacking-censys/817209/?utm_source=openai))

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Kubota Data Breach 2026: A Wake-Up Call for Industrial Cybersecurity
Impact· HIGH

Kubota Data Breach 2026: A Wake-Up Call for Industrial Cybersecurity

In early 2026, Kubota North America Corporation experienced a significant data breach where unauthorized actors accessed its network systems from March 16 to April 20. The intrusion led to the exposure of sensitive personal information belonging to employees and their dependents, including full names, Social Security numbers, dates of birth, taxpayer IDs, driver's license numbers, direct deposit bank account details, corporate payment card information, and benefits enrollment data. Kubota has since notified affected individuals and offered identity protection services to mitigate potential risks. This incident underscores the escalating threat landscape targeting industrial manufacturers, emphasizing the critical need for robust cybersecurity measures. The breach highlights the importance of proactive security protocols and continuous monitoring to safeguard sensitive employee data against unauthorized access and potential misuse.

2 months ago

Kill Chain

IC
Initial Compromise(low)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
ARToken: The Next Evolution in BEC-as-a-Service Platforms
Impact· HIGH

ARToken: The Next Evolution in BEC-as-a-Service Platforms

In April 2026, Cisco Talos identified ARToken, a sophisticated phishing platform linked to the EvilTokens phishing-as-a-service operation. ARToken is designed to bypass multi-factor authentication and compromise Microsoft 365 accounts, featuring advanced capabilities such as inbox rule manipulation and shared access links. The platform employs a seven-layer anti-analysis system to evade detection, and its phishing lures are highly targeted, often impersonating legitimate vendor communications to deceive accounts-payable staff into processing fraudulent invoices. The emergence of ARToken underscores a significant evolution in business email compromise (BEC) tactics, highlighting the increasing sophistication and accessibility of phishing-as-a-service platforms. This development poses a heightened risk to organizations, emphasizing the need for enhanced email security measures and employee vigilance against such targeted attacks.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports