On or around September 17, 2026, two threat actor groups, Metaencryptor and BrainCipher, publicly claimed to have breached the multinational infrastructure firm AECOM. The groups allege the theft of over 1.2 terabytes of corporate data. In response, the national class-action law firm Edelson Lechtzin LLP has initiated an investigation into potential data privacy failures at AECOM. The breach and the extent of the data compromise have not been officially confirmed by AECOM, but the public claims and subsequent legal investigation indicate a significant cybersecurity event with potential impacts on employees, clients, and partners whose data may have been exposed.
The incident came to light through posts on dark web monitoring sites. The threat group Metaencryptor first claimed responsibility on Ransomware.live, stating they had exfiltrated approximately 1.22 TB of data from AECOM. Concurrently, the dark web monitoring service Breachsense reported a separate but related data leak of around 670 GB, attributing it to a different actor named BrainCipher. This suggests a possible collaboration between the groups or a scenario where one group is a splinter or affiliate of the other. The attack appears to be a double-extortion scheme, where the primary leverage is the threat of public data release rather than encryption-based business disruption. The law firm's involvement signals concern that sensitive Personally Identifiable Information (PII) of current and former employees, as well as confidential client project data, may be at risk.
While specific technical details of the intrusion vector are not available, this incident aligns with common tactics used in large-scale data theft and extortion campaigns. The attack likely involved one or more of the following techniques:
T1566 - Phishing campaigns targeting employees, exploiting a vulnerability in an internet-facing system (T1190 - Exploit Public-Facing Application), or using stolen credentials.T1078 - Valid Accounts would be used to move across the network.T1560.001 - Archive via Utility) before exfiltrating it. The massive volume (over 1 TB) suggests the use of high-bandwidth channels, possibly through T1567 - Exfiltration Over Web Service to blend in with normal traffic.T1657 - Financial Theft), where the threat actors use the stolen data as leverage to demand payment.The involvement of two named groups, Metaencryptor and BrainCipher, could indicate a Ransomware-as-a-Service (RaaS) operation where one group provides the malware/infrastructure and the other (an affiliate) executes the attack.
The potential impact on AECOM is multifaceted and severe. The exposure of over a terabyte of data could include proprietary engineering designs, confidential client project details, financial records, and sensitive employee PII. This could lead to:
No specific Indicators of Compromise (IOCs) such as IP addresses, domains, or file hashes were mentioned in the source articles.
Security teams may want to hunt for the following patterns which could indicate activity similar to the claimed AECOM breach:
7z.exe a -p[password] -r [archive_name] [source_directory]rclone.exeDetecting and responding to such a large-scale data theft requires a multi-layered approach:
powershell.exe which then executes an archiving utility. Look for the execution of tools like rclone, megasync, or 7z in unexpected contexts.In response to a potential breach, the first steps should be to invoke the incident response plan, engage legal counsel, and work with a third-party cybersecurity firm to determine the scope of the intrusion, contain the threat, and preserve evidence for investigation.
Preventing large-scale data exfiltration requires both technical and procedural controls:
Implement comprehensive logging and auditing for file access, network traffic, and user account activity to detect anomalous behavior indicative of data staging and exfiltration.
Isolate critical data repositories on separate network segments with strict access controls to prevent attackers from easily moving laterally to access sensitive information.
Encrypt sensitive data at rest to ensure that even if data is stolen, it remains protected and unusable by the threat actor.
Train employees to recognize and report phishing attempts, which are a common initial access vector for these types of attacks.
Hacker group Metaencryptor claims to have attacked AECOM and stolen 1.22 TB of data. A separate leak is attributed to BrainCipher.
Edelson Lechtzin LLP announces an investigation into data privacy claims against AECOM.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.