Ransomware Groups Are Targeting Architecture, Engineering, and Construction Firms: What They Take and How They Get In
You might still think ransomware is a big-company problem. Something that happens to hospitals and giant corporations, not to a small architecture or engineering firm in Tennessee. That belief is exactly what the criminals are counting on, and it is out of date.

Construction and engineering are now a top-three target for ransomware, and the numbers are climbing faster here than almost anywhere else. The groups doing it have names, playbooks, and a real appetite for firms your size.
Here is the short version. Construction and engineering rank among the top three most-attacked sectors, and attacks on the sector jumped 41% in one year and another 44% year over year in early 2026. Attackers get in mostly through three doors: phishing, stolen passwords, and exposed remote access like VPN and RDP. Modern attacks do not just lock your files. They quietly steal your data first, then encrypt everything and threaten to leak what they took, and they hunt your backups too. The defense is a handful of basics done well: phishing-resistant MFA, locked-down remote access, patched systems, trained people, and immutable, tested backups. And you need a written plan for the worst day, with the phone calls in the right order.
Where construction really ranks
Let us be precise, because the numbers get inflated a lot in IT marketing.
Rapid7 tracked ransomware across every sector in 2025 and put construction in the top three most attacked sectors. Not first. Top three. ReliaQuest, which tracks the same leak sites, has professional and technical services in first place for five straight quarters, with manufacturing and construction right behind.
So construction is not the single most-hit industry. Anyone who tells you that is stretching it.
Here is what is actually alarming, and it is the growth rate. ReliaQuest counted 481 construction organizations posted to ransomware leak sites in one year, a 41% jump. In the first quarter of 2026, construction climbed from sixth place to fourth, with 131 victims posted, up 44% from the same quarter a year before.
Top three and climbing fast is a real problem. It does not need to be dressed up as number one.
Why they want you
A few reasons, and they are all about how your business works.
You move big money on tight deadlines. Projects run on large budgets and hard delivery dates. A firm facing a deadline is more likely to pay fast to get unstuck. They weaponize your schedule against you.
You work with a web of partners. Owners, GCs, subs, suppliers, consultants. That is a lot of connected firms sharing files, and attackers look for the weakest link, then use it to reach the others.
You often run older, looser systems. Small firms tend to have outdated software, unpatched machines, and security that grew by accident. Criminals scan for exactly that.
Your data is valuable. Beyond project files, your firm holds client information, employee records, legal documents, and financials. That is data worth stealing and worth threatening to leak.
One honest note here. The research on what Play ransomware goes after, private identification information, legal documents, and tax records, comes from tracking attacks on large construction companies. Nobody is publishing a study on what they take from a twelve-person architecture firm. But you hold the same categories of data on a smaller scale, and the leak sites are full of small firms.

How they get in: the three front doors
Almost every one of these attacks comes through one of three entrances.
The first is phishing. A convincing email tricks someone into clicking a link or handing over a password, and the attacker is in. Rapid7 lists phishing as one of the top ways into construction firms, partly because your workforce is spread across job sites and remote offices. When you cannot walk down the hall and ask “did you really send this?”, a fake request works better. We wrote a whole post on the phishing emails targeting AEC firms.
The second is stolen or reused passwords. Credentials leak constantly, and attackers try them against your email and systems. In construction, credential exposure now accounts for 75% of dark-web risk alerts for the sector, an 83% jump in a year. This is why shared logins and weak passwords are so dangerous, which we cover in our post on what small firms get wrong about passwords.
The third is exposed remote access. This one is bigger than most people think. The FBI and CISA looked at the Akira ransomware group and found the same pattern over and over: they got in through a VPN with no MFA turned on, usually by exploiting a known hole that had a patch available, or by using stolen VPN credentials, or by just guessing passwords until one worked. A remote desktop left open to the internet is the same story. We cover the setup in our post on VPN vs. remote desktop.
They do not smash through a wall. They walk in a door someone left unlocked: a clicked email, a reused password, an open remote connection.
What they actually do: double extortion
Here is the part that has changed, and it matters.
Ransomware used to just lock your files and demand payment to unlock them. The modern version is nastier. Normally what happens is: they steal your stuff, then they lock you out, then they threaten to publish what they stole. This is what the industry calls double extortion.
Here is the playbook. The attacker gets in, then quietly looks around your network for a while. They find your shared file servers and project folders. They copy your data out to their own systems. Only after they have it do they set off the ransomware and lock your files. Then you get hit with two threats at once. Pay to unlock your files. Pay again or we leak everything we took.
Sit with what that means. A perfect backup does not fully save you here. Backups get your files back. They do not un-steal the data. If the criminals already copied your clients’ information and your contracts, restoring from backup does not stop them from publishing it.
And they know about backups. Part of the playbook is finding and deleting them before they strike. This is not theory. One of the flaws Rapid7 saw exploited against this sector was a hole in Veeam backup software, the thing a lot of firms rely on to recover. They go after the lifeboat first.

“We’re too small” is the wrong read, but not for the reason you think
The most dangerous thought a small firm can have is “nobody would bother with us.”
Let us be straight about why that is wrong, because a lot of IT marketing gets this backwards. Criminals are usually not hand-picking your firm off a list. Most of this is automated scanning. They sweep the whole internet for open remote desktop ports, unpatched VPN boxes, and email accounts that show up in a password dump. Your firm name never comes up. Your open door does.
That is worse for you, not better. Being small does not hide you from a scanner. It just means you have fewer people watching the door.
There is a second angle. In construction, you are often connected to bigger partners through shared file platforms and project portals. That makes a small firm a soft way in to a larger target. Small fish, big pond, and the predators are not picky.
How to defend: the basics that actually stop this
Here is the honest good news. You do not need a giant security budget to stop most of this. Six things, and none of them are exotic:
- Turn on MFA everywhere, and make it the phishing-resistant kind. Multifactor authentication (MFA, a second step to log in beyond a password) means a stolen password is not enough to get in. Start with email and every remote access point.
- Lock down and patch remote access. Never leave a remote desktop open to the internet, keep your VPN patched, and require MFA to connect. This is the single door the Akira group walked through most often.
- Patch everything, on a schedule. Every flaw on Rapid7’s list of what hit this sector already had a patch available. We cover the AEC wrinkle in our post on why Autodesk software breaks after a Windows update.
- Run modern endpoint protection (EDR). Not old antivirus, but the kind that watches for bad behavior. It is also what your cyber insurance wants, covered in our post on answering a cyber insurance questionnaire.
- Train your people, including on phone calls. Attackers now call staff pretending to be the help desk, and that is not something an email filter catches.
- Keep immutable, offline, tested backups. Immutable means the backup cannot be changed or deleted once it is written. Follow the 3-2-1 approach in our post on why your firm needs a real backup plan.
Now the fine print, because three of those come with caveats most vendors will not lead with.
Not all MFA is equal anymore. Attackers now run fake login pages that pass your code straight through to the real site, and they call your staff pretending to be IT and ask for the code. Text-message codes and “approve this push” prompts can both be beaten this way. CISA calls FIDO security keys and passkeys the gold standard, because a fake site cannot use them. ReliaQuest says the same thing in its 2026 guidance. Start with MFA everywhere, since any MFA beats none. Then move email and admin accounts to security keys or passkeys. That is the upgrade path.
EDR is not a force field. Newer groups load a broken driver to shut EDR down at the deepest level of Windows right before they encrypt. Turning on Microsoft’s vulnerable driver block list closes that specific trick, and it is free.
Immutable is not magic, and “tested” has to mean something. If an attacker gets your backup console admin login, they can often shorten the retention setting or delete the whole account. So the backup console needs its own login, separate from your regular admin account, with its own MFA. And testing is not seeing a green checkmark. Testing is picking a random Revit central file from three weeks ago, restoring it to a spare machine, and opening it. Do that quarterly and write down how long it took. That number is your actual downtime.
If you already pay for Microsoft 365 Business Premium, you already own a lot of this. MFA, Conditional Access, Defender for Business, and Intune are all in that license. Most small firms we meet are paying for it and using almost none of it. Turning on what you already bought is the cheapest security project you will ever do.

If it happens anyway: the order of your phone calls matters
Even with good defenses, you want a plan for the worst day. Deciding mid-crisis is how firms make expensive mistakes.
Disconnect, do not destroy. Pull the affected machines off the network fast. Unplug the network cable or turn off the Wi-Fi. Do not power them down, and do not wipe and reinstall. Shutting down erases evidence that lives in memory, and the forensics team and your insurance carrier both need it.
Then make the calls, in this order.
- Your cyber insurance carrier. Call the breach hotline first. Most policies require their approval before you spend money on response, and many require you to use vendors from their approved list. If your IT provider starts forensic work before the carrier signs off, those costs may not be covered. We say that as your IT provider. Call them first.
- Your attorney, or the breach counsel the carrier assigns. Working through counsel can protect the investigation as privileged.
- Your IT provider. Once the carrier has approved the plan.
- The FBI, at https://www.ic3.gov.
Do not rush to pay, and know that paying may not be legal. The US Treasury has warned that making a ransom payment to a sanctioned group can itself break the law, and that risk falls on the victim and on anyone who helps make the payment. That decision goes through counsel and your carrier. Never straight to a crypto wallet.
Know your notification clock. In Tennessee, if a breach exposes personal information about state residents, you generally have 45 days from discovery to notify them. Tennessee also lets affected people sue over it, which most states do not. If you hold employee Social Security numbers, and you do, this applies to your firm.
A simple written incident response plan, decided ahead of time, is also one of the things cyber insurers commonly ask about on the application. It is the difference between a controlled response and a panic.
If you do federal or DoD work, the stakes are higher
This part matters around Knoxville, where a lot of firms touch federal, TVA, or DoD projects.
If your contracts involve federal contract information or controlled unclassified information, you likely already owe security controls under NIST 800-171. On top of that, the CMMC rules went live in November 2025, and contracting officers can now write CMMC requirements into new awards. Starting November 10, 2026, a third-party assessment becomes the standard for many of those contracts.
Translation: a ransomware incident is not just downtime and a leak. It can be a contract problem, a reporting obligation, and a question you have to answer on your next bid. If you do this kind of work and you are not sure where you stand, find out now, not after.
Frequently asked questions
We will make your firm a hard target
You do not have to become a security expert, and you do not need an enterprise budget. You need the basics set up right and kept up: MFA everywhere and phishing-resistant where it counts, remote access locked down, systems patched, people trained, and backups that actually survive an attack and get tested. That is what we do for architecture, engineering, and construction firms around Knoxville.
If ransomware groups are working through the construction sector, and the numbers say they are, give us a call. We will look at your doors, lock the ones standing open, and set up the protection that turns you from easy prey into a firm the criminals skip. So your team can focus on the work, not on the worst day.
Key takeaways
- Construction and engineering are a top-three ransomware target, not the number one target, and the growth rate is what should worry you: up 41% in a year, and up another 44% year over year in early 2026. Most attacks come from automated scanning, so being small is not camouflage.
- Attacks come through three doors: phishing, stolen passwords, and exposed remote access, with unpatched VPNs and missing MFA leading the pack. Modern ransomware is double extortion. They steal your data before they lock it, they threaten to leak it, and they go after your backups first.
- The defense is basics done well: phishing-resistant MFA, locked-down and patched remote access, modern endpoint protection, trained staff, and immutable backups you actually test. Have a written plan, and call your insurance carrier before you call anyone else.
Would a scanner find an open door at your firm?
We check the ways in, lock the ones standing open, and set up the MFA and backups that make your firm a hard target. No obligation, no sales pitch.
Sources: Threat Landscape of the Building and Construction Sector Part Two: Ransomware (Rapid7); Threat Landscape of the Building and Construction Sector Part One (Rapid7); Report Shows Ransomware Has Grown 41% for Construction Industry (ReliaQuest); Ransomware and Cyber Extortion in Q1 2026 (ReliaQuest); Ransomware and Cyber Extortion in Q2 2026 (ReliaQuest); #StopRansomware: Akira Ransomware, AA24-109A (CISA and FBI); Implementing Phishing-Resistant MFA (CISA); Updated Advisory on Potential Sanctions Risks for Facilitating Ransomware Payments (US Treasury OFAC); Tenn. Code Ann. 47-18-2107, Release of personal consumer information; DFARS 252.204-7021, Contractor Compliance With CMMC Level Requirements; FBI Internet Crime Complaint Center




