Quick Summary
AllegedExecutive Summary
AECOM, a global US-based infrastructure and engineering firm, has been identified as an alleged victim on MetaEncryptor’s dark web portal, with the listing dated September 17, 2026. This intelligence was surfaced by SOCRadar’s Dark Web Monitoring service. It is important to note that this is an allegation made by the threat actor and does not represent a confirmed breach. The nature of AECOM’s business, operating in the critical infrastructure and engineering sector, and its substantial enterprise size, make it a potential target for ransomware operations seeking high-impact disruptions and significant financial gain. MetaEncryptor has been an active threat actor, claiming 16 victims in the past 60 days. Their targeting appears focused on sectors including Manufacturing, Healthcare, and Professional Services, with a primary concentration of victims located in the United States, Japan, and Canada. AECOM’s profile as a large US-based professional services company aligns precisely with MetaEncryptor’s established targeting patterns. Previous victims attributed to this group include Promantra, Inc., Beckman Coulter, Inc., Hologic, Inc., and SIFCO Industries INC., indicating a consistent modus operandi across their recent activities.
Technical Analysis
SOCRadar’s investigation into aecom[.]com revealed a significant credential exposure risk through a stealer-log query, with critical timing details aligning with the ransomware listing date. The query, examining 25 records, identified several concerning findings. Four employee credentials were found to be targeting organizational systems, specifically impacting Okta-based Single Sign-On (SSO), a corporate VPN endpoint, and Webex conferencing services. Additionally, one corporate user credential was identified on a third-party recruiting platform. A separate finding noted 19 external applicant credentials associated with AECOM’s public job portal. While these do not represent direct internal access, they do pose a potential risk for account takeover (ATO) and credential stuffing attacks. The most critical finding is that these exposed credentials were logged between September 16 and September 17, 2026, with Okta and VPN credentials logged on the same day as the MetaEncryptor listing. This close timing is highly indicative of active pre-ransomware credential validation, where threat actors test and confirm the viability of stolen credentials before deploying ransomware. The exposure of Okta SSO and VPN credentials presents a live intrusion risk for AECOM. Immediate action is recommended to rotate all identified @aecom.com credentials associated with these identity and VPN systems, without awaiting further confirmation of a breach. Prioritizing the audit of session logs dating back to September 16 is crucial for understanding the scope of potential unauthorized access. The 19 applicant records on the job portal represent a secondary, lower-urgency concern related to ATO risks.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.