Engineering (Includes Industrial Construction)

Industry

Cyberattack at Engineering Company Othon

March 11, 2026

Houston, Texas-based engineering company, Othon, Inc., suffered a cyberattack in March where personally identifiable information ended up stolen in the hack.
“On March 12, 2026, Othon became aware of suspicious activity on certain computer systems in its network,” the company said in a notice to victims of the attack. “Othon acted promptly to secure its systems and launched a comprehensive investigation, with the assistance of third-party forensic specialists, to confirm the full nature and scope of the event.”
As a result of the investigation, the company found between March 11 and March 12 certain files within its network ended up accessed and/or downloaded without authorization.

read more

Engineering Firm, Asplundh Engineering Services Hit in Attack

January 11, 2026

Ambler, Pennsylvania-based Engineering company, Asplundh Engineering Services, LLC, suffered a cyberattack in January where personally identifiable information ended up stolen in the hack.
“On or around January 18, 2026, Asplundh Engineering identified suspicious activity on their computer network,” the company said in a notice to victims. “Upon becoming aware of this activity, Asplundh Engineering quickly took steps to secure the environment, with the assistance of third-party specialists, and launched an investigation into the nature and scope of the activity.”
The investigation found an unauthorized actor accessed their network at various times between January 11, 2026 and January 17, 2026 and, during that period, accessed and copied certain files and information from the network.

read more

Engineering Firm MasTec Suffers Cyberattack

August 9, 2025

Coral Gables, Florida-based engineering firm, MasTec, Inc., suffered a cyberattack last August and is now letting victims know their personally identifiable information ended up stolen in the attack..
“In early October 2025, we received reports of suspicious activity in a small portion of our computer network,” the company said in a notice to its victims. “We promptly began working with third-party cybersecurity experts to investigate and remediate that activity.”
Later on that month, the company said the investigation found an unauthorized third party gained access to a small portion of our computer network for a few days in August 2025.

read more

Cyberattack at Engineering Firm Lamb-Star Engineering

January 20, 2026

Frisco, Texas-based engineering firm Lamb-Star Engineering, LLC, suffered a cyberattack in January and is now letting victim know their personally identifiable information ended up stolen in the hack.
“On or about January 20, 2026, Lamb-Star detected suspicious activity on its system,” the company said in a notice to victims. “Upon discovery of this incident, Lamb-Star immediately disconnected the affected systems and remote access to the network.”
The company then hired a specialized third-party cybersecurity firm and IT personnel to assist with securing the environment, as well as to conduct a comprehensive forensic investigation to determine the nature and scope of the incident.

read more

Cyberattack at Chemical & Industrial Engineering

June 9, 2025

Louisville, Kentucky-based engineering firm, Chemical & Industrial Engineering Inc. (C&I) , suffered a cyberattack last June and is now letting victims know their personally identifiable information ended up stolen in the hack.
“In early August 2025, we detected suspicious activity in a portion of our computer network,” the company said in a letter to victims. “We promptly began working with third-party cybersecurity experts to investigate and remediate that activity.”
The investigation found an unauthorized third party gained access to some of the company’s computer network from June to August 2025.

read more

Engineering Firm, Pickett and Associates, Attacked, Stolen Info For Sale

January 5, 2026

A Tampa, Florida-based civil engineering, surveying, and geospatial services firm for utilities and mining operations, suffered a cyberattack and had sensitive client data stolen.
Threat actors posted a new thread on a dark web forum Monday claiming to have stolen more than 800 files from the engineering firm, Pickett and Associates, according to a report from Tech Radar. The data is “real, operational engineering data from active projects of major utilities and is suitable for infrastructure analysis and risk assessment,” the attackers said on their site.
The attacker in this case is Zestix, which also has links to the online persona Sentap, according to Hudson Rock, which specializes in cybercrime intelligence, safeguarding against infostealer-based cyberattacks. The threat actor is an initial access broker (IAB) which also exfiltrates victim data and sells it on hacker forums.

read more

Architectural And Engineering Firm Hit in Cyberattack

September 13, 2024

Architectural and engineering provider, Baskervill & Son, P.C & Son, P.C. suffered a cyberattack last September and is now informing victims of the incident their personally identifiable information ended up stolen.
“On September 13, 2024, we learned of an unauthorized access to our systems,” the company said in a notice to victims. “Upon detection, we took immediate action to terminate further access and investigate the incident. We retained legal counsel and, through counsel, engaged external cybersecurity forensic specialists to conduct an investigation.”
On October 23, the forensic investigation revealed on September 13, an unauthorized actor gained access to and exfiltrated data from the Richmond, Virginia-based company’s systems.

read more

Cyberattack at NY Engineering Firm

September 24, 2025

Skaneateles Falls, New York-based Ryan Biggs Clark Davis Engineering, DPC (RBCD), suffered a cyberattack via a business email compromise in September where personally identifiable information ended up stolen in the attack.
“On September 24, 2025, RBCD was subject to a data security incident,” the company said in a notice to victims. “As a result of the incident, an unauthorized actor temporarily obtained access to an employee email data.”
Upon detecting the incident, RBCD contained the threat, and immediately commenced a prompt and thorough investigation.

read more

Engineering Firm, GlobalLogic, Victim Of Oracle Breach

October 9, 2025

Santa Clara, California-based digital engineering provider, GlobalLogic Inc., fell victim to an attack starting in July through an Oracle Zero Day where former and current employees had some personally identifiable information stolen.
On October 4, Oracle issued a security advisory regarding a previously unknown Zero Day exploit. GlobalLogic uses Oracle E-Business Suite, a collection of applications, to manage core business functions such as finance, HR, accounts payable and receivable.
“As soon as we learned of the vulnerability, GlobalLogic immediately investigated and determined that it had been exploited within our instance of Oracle,” the company said in a letter to its victims. “Once we made this determination, we activated our incident response procedures, engaged leading third-party cybersecurity experts to assist in a comprehensive investigation, and notified law enforcement.”

read more

Aussie Fluid Power Hit by Cyberattack

October 16, 2025

Aussie Fluid Power experienced a security incident involving unauthorized access to its IT systems. “While the investigation is ongoing, at this stage it appears the event may have resulted in certain employee, customer, and supplier information being compromised.”

Ransomware group Anubis claimed responsibility for the attack.

read more