Home Blog TX Construction Threat Brief

Download the PDF Version

Print-ready for your team, board, or compliance review. Email-gated — takes 30 seconds.

Download PDF →

Construction is the #2–3 most targeted sector globally for ransomware in 2024–2025. In Texas, that translates to a $80B+ annual industry running its payment workflows over email — draw requests, lien releases, subcontractor ACH changes — with minimal verification. The Akira ransomware group claimed Williams Brothers Construction in February 2026. A Texas GC lost $2.5M in a single BEC wire the same year, with only $776K recovered. FBI IC3 ranks construction in the top 3 for BEC and ransomware losses nationally.

41%
increase in construction ransomware attacks 2023–2024 (ReliaQuest)
$4.2M
average ransomware cost per breach in construction (IBM/CISA via Procore)
21 days
average ransomware downtime — every hour on an active job has cascading cost

Six Incidents Defining the Construction Threat Landscape

These are not hypothetical scenarios. They are documented incidents that hit GCs, government contractors, and construction-adjacent firms — some in Texas, all directly relevant to how Texas GCs operate.

Williams Brothers Construction — Akira
February 2026  ·  United States
Akira ransomware group listed Williams Brothers Construction as a victim in February 2026, alleging theft of employee files, financial records, and project data. Double-extortion model: data theft plus encryption threat. Akira is an established RaaS group that specifically targets mid-market businesses in construction, manufacturing, and technology sectors using credential-based intrusion.
Impact: Data exfiltration + encryption threat  ·  Double-extortion
Sources: ransomware.live, integratecyber.com
Texas GC — BEC Draw Wire Fraud
2024  ·  Texas
A BEC syndicate impersonated a contractor and requested a change of payment bank account for a draw request. The county processed the payment without direct callback verification. $2.5M wired. Only $776K recovered. $1.7M unrecovered, dispersed through multiple accounts before the fraud was detected. This was part of a nationwide campaign targeting government–contractor payment relationships — the exact billing structure that governs most Texas municipal construction projects.
Loss: $2.5M wired  ·  $1.7M unrecovered
Sources: Eftsure US, FBI IC3 complaint data
Bouygues Construction — Maze Ransomware
January 2020  ·  France (global operations)
Maze ransomware group encrypted approximately 237 computers and potentially exfiltrated ~1,000 TB of data across Bouygues' global IT network. The attack was one of the first to use Maze's double-extortion model at scale — encrypt and threaten to publish. Bouygues was a global top-10 GC. The attack demonstrated that even firms with substantial IT budgets are vulnerable to ransomware campaigns targeting the construction sector specifically.
Ransom demand: ~€10M  ·  Global IT shutdown
Sources: multiple cybersecurity outlets, January 2020
BAM Construct UK — Hospital Project Disruption
Early 2020  ·  United Kingdom
An unnamed ransomware group attacked BAM Construct UK, forcing the company to take its website and multiple internal systems offline to neutralize the attack. NHS hospital construction projects in Yorkshire and Humber were disrupted. Texas GCs working on VA hospital construction, DoD medical facilities, and healthcare campus projects face identical exposure — a breach during active construction can halt projects with no-pause deadlines.
Impact: Hospital construction projects disrupted  ·  Internal systems offline
Sources: UK construction press, parent company (Royal BAM Group) disclosures
Suffolk County, NY — $25M Recovery Cost
September 2022  ·  New York
AlphV/BlackCat ransomware group stole approximately 4 terabytes of data including sensitive government records. County services were disrupted for months. Total recovery cost exceeded $25M through 2023–2024. Investigators revealed ignored security warnings and lack of preparedness as root causes. The government-contractor payment relationships disrupted by this attack are structurally identical to Texas municipal construction billing workflows.
Recovery cost: $25M+  ·  Services disrupted for months
Sources: Suffolk County government disclosures, Newsday, government technology outlets
Halliburton TX Operations — Energy/Construction Supply Chain
October 2024  ·  Texas
Ransomware disrupted Halliburton's Texas information systems, causing multi-million dollar incident response and recovery costs as confirmed in regulatory filings. The attack is relevant to TX construction because many GCs — especially in Permian Basin, Eagle Ford, and Houston Ship Channel — work on petrochemical and energy facility construction projects where they are direct supply chain partners to firms like Halliburton. Ransomware groups actively targeting TX energy sector are hitting adjacent construction and supply chain firms.
Impact: Multi-million dollar IR & recovery  ·  TX energy supply chain
Sources: Recorded Future News, regulatory filings, BlueRadius TX cybersecurity report 2025

The BEC Wire Fraud Kill Chain for Construction

Business Email Compromise draw fraud is the construction sector's most financially damaging threat — and the most preventable. The FBI IC3 documented $3B+ in BEC losses in 2025 alone. In construction specifically, the attack has a predictable pattern:

  1. 01
    Reconnaissance: Attackers identify a GC working on a large project (public bid databases, county procurement records, SAM.gov). Payment schedules and billing contacts are often in public documents.
  2. 02
    Email compromise or lookalike domain: The attacker either compromises a subcontractor's email (via phishing or credential stuffing) or registers a lookalike domain (e.g., "acme-construction-tx.com" vs "acmeconstruction-tx.com").
  3. 03
    Bank change request: A routine-looking email requests a change of banking information for an upcoming draw, lien release, or progress payment. The timing coincides with a known payment milestone.
  4. 04
    Wire processed without verification: The finance team, under schedule pressure, processes the payment change without calling the vendor on a known-good number. The window between wire initiation and detection is typically 2–4 hours.
  5. 05
    Funds dispersed: The wire hits the fraudulent account, which is immediately swept to multiple accounts and international transfers. Recovery window: hours. After 24 hours, recovery rates drop below 30%.
The $2.5M Texas BEC Lesson
The documented 2024 Texas construction BEC case had one preventable failure point: no callback verification on the bank change request. A written SOP requiring a direct phone call to a known-good number before any ACH/wire change — regardless of urgency — would have stopped this attack entirely. The fix costs nothing. The failure cost $1.7M after partial recovery.

Ransomware on Project File Servers: The 21-Day Shutdown

Ransomware targeting construction project file servers hits differently than generic corporate ransomware. The impact is not just data loss — it's job site paralysis. CAD files, BIM models, schedules, RFIs, submittals, and estimating databases are the operational heartbeat of an active project. When ransomware encrypts them, the consequences include:

The Regulatory Stack: TDPSA, CMMC 2.0, and FAR 52.204-21

Texas construction GCs face a four-layer regulatory exposure. The overlapping obligations create both risk and competitive advantage — firms that get ahead of compliance have a demonstrable edge in federal and municipal procurement.

Texas State Law · Active
TDPSA — Texas Data Privacy and Security Act
Effective July 1, 2024. Employee PII (SSNs, I-9s, direct deposit, health plan data), subcontractor payroll, client W-9 data, and project records are all in scope. $7,500 per violation civil penalties enforced by the TX Attorney General. 45-day response window to consumer requests. Data protection assessments required for high-risk processing. TX AG has already settled $1.4B with Meta and $3.5M with Marriott — enforcement is real.
Federal · Phase 2 Begins Nov 2026
CMMC 2.0 — Cybersecurity Maturity Model Certification
32 CFR Part 170 + DFARS 252.204-7021. GCs and subs touching DoD installations in TX — Fort Cavazos, JBSA, Lackland, Fort Bliss, Corpus Christi NAS, Red River Army Depot — need CMMC Level 2 for CUI-handling contracts. No valid certification = no DoD contract eligibility. Phase 2 mandatory C3PAO assessments begin November 2026. C3PAO wait times are already 6–12 months nationally. The window to prepare is now.
Federal · Active Now
FAR 52.204-21 — Basic Safeguarding of Federal Contract Systems
Applies to any contractor with a federal contract involving Federal Contract Information (FCI). Requires 15 basic safeguarding requirements — essentially CMMC Level 1. Every federal construction contract has this active today. Non-compliance risks contract suspension and debarment. The 15 controls (access control, configuration management, identification and authentication, system and communications protection, system and information integrity) are the floor, not the ceiling.
Federal · NIST Framework
NIST SP 800-171 Rev 2 — Protecting CUI in Nonfederal Systems
110 controls across 14 families. Contractors must maintain and submit a self-assessment score to the DoD Supplier Performance Risk System (SPRS) — and defend that score during a C3PAO assessment. The score must be current. An outdated or unsubmitted SPRS score is a red flag in federal procurement. GCs need operational security programs that produce the evidence SPRS and C3PAO assessors look for — not just a gap-assessment spreadsheet.

IRS WISP — A Requirement for GCs with Employee and Payroll Data

One frequently missed compliance requirement: the IRS Written Information Security Plan (WISP), mandated under the Safeguards Rule for any business that handles employee tax information. For GCs with W-2 employees and 1099 subcontractors, the WISP requirements include designated personnel, access controls, incident response procedures, and annual risk assessments. The IRS Publication 4557 provides the framework. This overlaps significantly with TDPSA's administrative safeguards requirement — a well-structured CoreRecon engagement covers both simultaneously.

30/60/90 Hardening Roadmap for Texas GCs

Days 1–30: Stop the Most Likely Losses

  1. 1
    Enable MFA on all email and accounting software — Microsoft 365/Google Workspace, Sage/Viewpoint/QuickBooks, and any ERP. Before end of Month 1. This is the single highest-ROI security investment for a GC.
  2. 2
    Implement callback verification SOP — any change of payment bank account triggers a direct phone call to the requestor on a known-good number before processing. Write it down. Sign it off. Train the finance team. This alone stops the $2.5M BEC scenario.
  3. 3
    Deploy managed EDR on all endpoints — office computers, field laptops, project manager tablets. Prioritize finance team and PM computers first. A field laptop is often the first device compromised.
  4. 4
    Verify backup integrity — confirm existing backups are running, test a restore, and move at least one backup copy offline/immutable. In 2024, 94% of ransomware attacks targeted backups first.
  5. 5
    Write a one-page IR quick reference — legal counsel contact, IT provider, cyber insurance claim number, and FBI IC3 filing process (ic3.gov). Post it. Do not search for this during an active incident.

Days 31–60: Layered Defense

  1. 1
    Segment project file servers from general corporate network. Ransomware spreading from IT to file servers was the mechanism in the Bouygues and most other construction incidents. VLAN architecture documented in a System Security Plan (SSP).
  2. 2
    Harden email security — implement SPF, DKIM, DMARC with p=reject mode. Add BEC-specific email filtering tuned for construction payment workflow patterns. Lookalike domain detection.
  3. 3
    Audit Procore/Autodesk ACC access controls — review user permissions, enforce MFA on platform accounts, implement conditional access tied to device compliance. A compromised Procore account gives attackers visibility into your entire payment schedule.
  4. 4
    Begin subcontractor security survey — assess top 5 subs for basic controls (MFA, EDR). Establish minimum requirements for future subcontracts. DFARS flow-down means your CMMC exposure includes your sub tier.

Days 61–90: Compliance and Resilience

  1. 1
    CMMC gap assessment — if you work on any DoD project in Texas, conduct a NIST SP 800-171 gap assessment and build your POA&M now. Phase 2 C3PAO assessments begin November 2026. Assessment wait times are already 6–12 months.
  2. 2
    TDPSA data mapping — identify all personal data covered by TDPSA (employee records, subcontractor payroll, W-9s, client data). Document data flows and consumer rights fulfillment process.
  3. 3
    Cyber insurance review — confirm your policy covers wire fraud/BEC AND ransomware, and that you can demonstrate the controls your insurer requires. 40%+ of claims were denied in 2024 due to missing MFA, EDR, or backup testing documentation.

The SDVOSB Advantage for Federal Construction GCs

Service-Disabled Veteran-Owned Small Business (SDVOSB) certification opens federal set-aside competition pathways at Fort Cavazos, JBSA, Lackland AFB, Fort Bliss, Corpus Christi NAS, and Red River Army Depot. For federal construction GCs in Texas, working with an SDVOSB cybersecurity partner who understands CMMC 2.0 creates two advantages: (1) it checks a federal procurement requirement box while securing your network, and (2) it gives you a cybersecurity partner who has been through the DoD compliance documentation process before and knows what C3PAO assessors actually look for in an evidence package.

CoreRecon is SDVOSB-certified, Texas-based, and the only MSSP in the state with published pricing and a documented 30-minute SLA for construction sector clients.

Get Your TX Construction Security Assessment

30-minute call with a construction security specialist. We review your BEC exposure, CMMC gap, project file server topology, and EDR coverage — at no cost. Written report delivered in 14 days.

Get Free Assessment →

Or download the full TX Construction Threat Brief (PDF) with 32 verified sources.

Sources (32 citations): FBI IC3 — Business Email Compromise: The $50 Billion Scam (PSA 2023) • FBI IC3 — 2025 IC3 Annual Report ($20.877B losses) • FBI IC3 — BEC Statistics Page • Eftsure US — "$7.7 million fraud: how US BEC scams hit construction and government sectors" • ENR — "Justice Served: Scammer Sentenced in Major Construction Payment Fraud" • ReliaQuest — "Report Shows Ransomware Has Grown 41% for Construction Industry" (Nov 2024) • Preactive IT Solutions — "Ransomware Defense for Construction and Engineering Firms" • Construction Dive — "Tech adoption makes construction industry top target for cyberattacks" • Construction Dive — "US construction tech firms brace for increased cyberattacks" • Corvus Insurance — "Cyber Threat Landscape & Digital Threats in the Construction Industry" • IntegrateCyber — "Construction Ransomware Attacks" (Williams Brothers / Akira, Feb 2026) • ransomware.live — Ransomware tracking database • Hunter Strategy — "Ransomware Surge Against Construction Firms" • Rapid7 — "Threat Landscape of the Building and Construction Sector Part Two: Ransomware" • The Record from Recorded Future News — "Texas-based oilfield supplier faces disruptions" • BlueRadius — "Texas Cybersecurity Breach Report 2025: $1.35B Losses, 41K Complaints" • Procore — "Protecting Your Project Data: Key Cybersecurity Takeaways" (CISA/IBM data) • VQIS — "Does Your Construction Software Stack Carry Cybersecurity Risk?" • Reddit r/Construction — "PSA: Procore might be compromised" • Reddit r/ProCore — "What's happening at Procore?" • Texas Attorney General — TDPSA guidance • Texas AG Public Information Act Handbook (2026) • Texas Comptroller — The Public Information Act • Texas Construction Law Blog — "Constructing Compliance: TX Data Privacy and Security Act" • Construction Pros Insurance Services — "Texas Cyber Insurance for Contractors 2026" • LayerLogix — "Cybersecurity Threats for Houston Businesses in 2026" (40%+ claim denial) • Brock Insurance Group — "Texas Cyber Risk Management: Practical Playbook" • NorthStar Technology Group — "Supply Chain Cybersecurity for DoD Contractors" • Infonaligy — "CMMC Phase 2: What Texas Contractors Must Do by Nov 2026" • NIST SP 800-171 Rev 2 — Protecting CUI in Nonfederal Systems (csrc.nist.gov) • Suffolk County government disclosures, Newsday, government technology outlets (Sep 2022) • UK construction press, Royal BAM Group disclosures (early 2020)