HackerFeeds
All ransomware incidents
aecom.com

Ransomware group metaencryptor hits AECOM

MEDIUM
·Professional Services·US·2026-09-17

AECOM — a professional services target operating in US has been listed by the metaencryptor ransomware group on 2026-09-17. The information below reflects what the threat actor has publicly claimed on their leak site; the details have not been independently verified.

Incident Report

Target OrganizationAECOM
Threat Group
metaencryptor
SummaryAECOM is a leading U.S.-based global infrastructure consulting and engineering company. It provides design, engineering, construction management, and advisory services for major infrastructure projects across transportation, water, energy, buildings, environmental services, and government markets. AECOM operates worldwide and serves public- and private-sector clients.
Date of Breach2026-09-17
Discovery Date2026-09-17
RegionUS
Target Domainaecom.com
Business SectorProfessional Services
Severity
MEDIUM

Claim by metaencryptor

AECOM is a leading U.S.-based global infrastructure consulting and engineering company. It provides design, engineering, construction management, and advisory services for major infrastructure projects across transportation, water, energy, buildings, environmental services, and government markets. AECOM operates worldwide and serves public- and private-sector clients.

Posted by the metaencryptor threat actor on its public leak site. This is the group's own statement and has not been independently verified by HackerFeeds.

Sources

Victim website

aecom.com

Leak post (onion / Tor)

tor

https://metacrpttdfpbm4qoxzcrqqgr6e6zafpazgxm72knmujw2mwvi34rwad.onion/0AFC:f59088f2478cb682d8411fe9c50d0b587bb1b418afffb1f1447b95f0ebf69cef/0AFC:bfd01c503339b09aa9c70b64d042ae29ee8a1503f6dc41e58d4dc3ab0664a9a6

Open this URL in Tor Browser. Browsing leak sites carries real risk — view passively, never click further.

Disclaimer

HackerFeeds does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.