CoreRecon Intelligence Report  •  June 2026

Texas Construction
Cyber Threat Brief
2026

41% ransomware surge in construction 2023–2024. Williams Brothers Construction (Akira, Feb 2026). Texas GC $2.5M BEC wire loss. CMMC 2.0 Phase 2 enforcement begins November 2026. Full sector analysis, BEC wire fraud kill chain, and 8 controls for TX GCs. 32 verified sources.

41%
construction ransomware
surge 2023–2024
$4.2M
avg breach cost
in construction
$2.5M
TX GC BEC loss
2024 (documented)
Nov 2026
CMMC Phase 2
enforcement begins
Download Full Brief (PDF) Get Free Security Assessment
Sources: ReliaQuest Ransomware Report 2024 • FBI IC3 2025 • Eftsure US • integratecyber.com • IBM CODB 2025 • CMMC 2.0 Program Office • Texas AG TDPSA guidance • NIST SP 800-171 Rev 2 • 26 additional verified sources

Construction is a
preferred ransomware target

FBI IC3 ranks construction in the top 3 sectors by BEC and ransomware losses nationally. ReliaQuest documented a 41% increase in construction ransomware attacks between 2023 and 2024. Corvus Insurance confirmed construction among the most targeted sectors for ransomware globally in 2024–2025. Texas construction represents $80B+ in annual activity — the scale of payment flows and the fragmentation of the supply chain make it uniquely vulnerable to BEC wire fraud.

Entity Attribution Impact Cost/Loss
Williams Brothers Construction
United States
February 2026
Akira ransomware group
Data exfiltration + encryption threat. Employee files, financial records, project data alleged stolen. Double-extortion model.
Data theft + extortion
Texas GC — BEC Wire Fraud
Texas
2024
BEC syndicate (unnamed)
Contractor impersonation; bank change request on draw payment; no callback verification; funds dispersed through multiple accounts before detection.
$2.5M wired / $776K recovered
Bouygues Construction
France (global GC)
January 2020
Maze ransomware group
~237 computers encrypted. ~1,000 TB data potentially exfiltrated. Global IT network shutdown. Double-extortion pioneer.
~€10M ransom demand
BAM Construct UK
United Kingdom
Early 2020
Unnamed ransomware
Website and internal systems offline. NHS hospital construction projects (Yorkshire/Humber) disrupted. Royal BAM Group involved in recovery.
Hospital projects disrupted
Suffolk County, NY (Gov't-GC payments)
New York
September 2022
AlphV/BlackCat
~4 TB stolen. County services disrupted for months. Government-contractor payment infrastructure compromised.
$25M+ recovery cost
Halliburton TX Operations
Texas
October 2024
Unnamed ransomware
TX information systems disrupted. Multi-million dollar IR/recovery. Energy/construction supply chain impacted.
Multi-million IR & recovery
TX exposure: FBI IC3 documents Texas in the top 3 states by IC3 complaints annually. The documented $2.5M TX BEC loss involved a government–contractor draw payment with no callback verification — an exact replica of standard Texas municipal construction billing workflow.

Construction-specific amplifiers: Ransomware attacks on construction increased 41% between 2023–2024 (ReliaQuest). Phishing attacks on construction increased 83% in the same period. Nearly half of construction firms reported experiencing a cyber attack in the past year (CISA/IBM 2024).

How the $2.5M Texas wire
actually happened

BEC draw fraud is the construction sector's most financially damaging and most preventable threat. The FBI IC3 documented $3B+ in BEC losses in 2025. In construction, the attack targets the payment workflow at the moment of highest trust and urgency.

1. Reconnaissance
Attackers identify a GC working on a large project via public bid databases, county procurement records, SAM.gov. Payment schedules and billing contacts are often in public documents. No technical skill required for this phase.
2. Email Compromise
The attacker compromises a subcontractor's email (phishing/credential stuffing) or registers a lookalike domain. Procore credential compromise gives attackers visibility into payment schedules — enabling precisely timed fraud emails.
3. Bank Change Request
A routine-looking email requests a change of banking information for an upcoming draw, lien release, or progress payment. Timing coincides with a known payment milestone. The email looks legitimate — because the attacker knows the relationship.
4. Wire Processed
The finance team, under schedule pressure, processes the payment change without calling the vendor on a known-good number. This is the single failure point that stops BEC cold — a callback SOP breaks the chain entirely.
5. Funds Dispersed
The wire hits the fraudulent account, immediately swept to multiple accounts and international transfers. Recovery window: 2–4 hours. After 24 hours, recovery rates drop below 30%. In the TX case: $2.5M out, $776K recovered.
The Single Fix
Callback verification SOP: Any change of payment bank account triggers a direct phone call to the requestor on a known-good number before processing. Write it. Train it. Enforce it. This is the entire defense against BEC draw fraud — and it costs nothing.

Four regulatory regimes
converging on TX GCs

Texas State Law · Active
TDPSA
Effective July 1, 2024. Employee PII (SSNs, I-9s, payroll), subcontractor W-9 data, client records all in scope. $7,500/violation civil penalties. 45-day consumer request response window. TX AG enforcement posture: $1.4B Meta settlement, $3.5M Marriott settlement — dedicated privacy enforcement team active.

Source: TX Attorney General, Texas Construction Law Blog
Federal · Phase 2 Nov 2026
CMMC 2.0
32 CFR Part 170 + DFARS 252.204-7021. Mandatory C3PAO assessments begin November 2026. TX DoD installations: Fort Cavazos, JBSA, Lackland, Fort Bliss, Corpus Christi NAS, Red River Army Depot. No valid CMMC = no DoD contract eligibility. C3PAO wait times: 6–12 months nationally — assessment slots filling now.

Source: CMMC 2.0 Program Office, Infonaligy, NorthStar Technology Group
Federal · Active Now
FAR 52.204-21
Applies to any contractor with a federal contract involving Federal Contract Information (FCI). Requires 15 basic safeguarding controls — essentially CMMC Level 1. Every federal construction contract has this active today. Non-compliance risks contract suspension and debarment. These 15 controls are the floor for federal GC compliance.

Source: FAR clause, DoD/FBI cybersecurity guidance for contractors
Federal · NIST Framework
NIST SP 800-171 Rev 2
110 controls across 14 families for GCs handling CUI on DoD projects. SPRS score must be maintained and submitted. An outdated or unsubmitted SPRS score is a red flag in federal procurement. Contractors need operational security programs that produce the evidence SPRS and C3PAO assessors look for — not just a gap-assessment spreadsheet.

Source: NIST SP 800-171 Rev 2 (csrc.nist.gov), DFARS 252.204-7012

8 controls for
TX construction operations

01
MFA on Financial Systems & Email
Microsoft 365/Google Workspace, Sage/Viewpoint/QuickBooks, ERP, VPN/RDP. BEC and ransomware both start with credential compromise.
Nearly all cyber insurers require MFA as a baseline condition — failure to implement is grounds for claim denial. This is the single highest-ROI security investment for a GC.
02
Callback Verification SOP
Any change of payment bank account triggers a direct phone call to the requestor on a known-good number before processing. Written SOP, staff training, enforcement.
The documented 2024 Texas BEC case had one preventable failure: no callback verification. This SOP stops BEC draw fraud entirely — zero cost to implement.
03
Managed EDR — All Endpoints Including Field
Endpoint Detection & Response with behavioral analysis on all devices — office, field laptops, project manager tablets, and mobile running Procore/ACC.
Field laptops are the most common ransomware entry point and the least secured. Managed EDR with 24/7 SOC response reduces 21-day average downtime to hours.
04
Project File Server Segmentation
Isolate CAD/BIM/schedule/RFI servers from general corporate network and internet-facing systems. VLAN architecture documented in SSP.
A flat network lets ransomware spread from one field laptop to every project file. Segmentation limits the blast radius to a single device, not the whole firm.
05
Procore/Autodesk ACC Access Controls
Audit permissions on project management platforms. Enforce MFA + conditional access tied to device compliance. Review user access quarterly.
Compromised Procore credentials give attackers visibility into your payment schedule. Reddit r/Construction documented a 2024 Procore credential compromise incident.
06
Subcontractor Cybersecurity Requirements
Assess top subs before awarding work. Require MFA, breach notification, and minimum security controls in subcontract agreements. Monitor compliance.
DFARS requires primes to ensure sub compliance. Primes are increasingly requiring sub prequalification on cybersecurity. "My GC handles it" is not a compliance defense for subs.
07
CMMC Gap Assessment & POA&M
NIST SP 800-171 gap assessment and Plan of Action & Milestones build for GCs working on DoD TX installations. SPRS score documentation.
Phase 2 C3PAO assessments begin November 2026. C3PAO wait times: 6–12 months nationally. The preparation window is now. CoreRecon builds the operational evidence package C3PAO assessors look for.
08
Immutable Backup — Project File Servers
Offline, immutable backups of CAD/BIM, schedules, RFIs, submittals, estimating databases. Tested recovery with documented RTOs.
In 2024, 94% of ransomware attacks targeted backup infrastructure first. Standard NAS backups are not safe. Immutable, air-gapped backups are the only reliable recovery path.

Your path to
compliance readiness

Days 1–30
MFA, Callback SOP, EDR, Backup Verify
Enable MFA on all email and financial systems. Write and train callback verification SOP. Deploy managed EDR on all endpoints. Verify backup integrity and test restore. Write one-page IR quick reference.
Days 31–60
Segmentation, Email Security, Procore Audit
Segment project file servers from general network. Implement SPF/DKIM/DMARC with p=reject. Audit Procore/Autodesk ACC access controls and enforce MFA on platform accounts. Begin subcontractor security survey (top 5 subs).
Days 61–90
CMMC Gap Assessment, TDPSA Mapping
For DoD project GCs: conduct NIST SP 800-171 gap assessment and build POA&M. C3PAO wait times are 6–12 months — start now. Map TDPSA data flows across employee records, sub payroll, W-9s, client data.
Ongoing
SOC Coverage, Quarterly Testing, Annual IR Exercise
24/7 SOC coverage with 30-min SLA. Quarterly backup restore test (documented for insurers). Annual tabletop exercise with construction-specific scenarios (BEC draw fraud, ransomware during active project, subcontractor breach). SPRS score maintenance.

Built for TX construction.
30-min SLA.

30-Minute SLA
IBM CODB 2025: 241-day average detection time. A 21-day ransomware shutdown on an active job costs more than the ransom. CoreRecon's 30-min SLA means your project disruption is measured in hours, not weeks.
🎖️
SDVOSB Certified
Service-Disabled Veteran-Owned Small Business. SDVOSB positioning + CMMC Level 2 certification = competitive advantage in federal set-aside competitions at TX DoD installations.
🏗️
Construction-Sector Expertise
TX-based team with documented construction-sector security experience. We understand BEC draw fraud workflows, Procore/Autodesk attack surfaces, field laptop security, and CMMC flow-down requirements for sub tiers.
📋
CMMC + TDPSA In Scope
CMMC 2.0 gap assessment, SPRS documentation, and TDPSA compliance are included in CoreRecon's scope for construction clients. We map your controls to both mandates simultaneously.
💰
Published Pricing
Sentinel $89/endpoint. Fortress $129/endpoint. Command from $2,500/month. No "schedule a call to get a quote." TX GCs are sophisticated buyers — published pricing builds trust and reduces sales friction.
📍
Texas-Based
TX residency matters for TDPSA enforcement response, TX AG notice procedures, and understanding the TX construction market (semiconductor boom, DoD base expansion, Permian Basin energy construction).

Three ways to
protect your GC

🔍
Free Security Assessment
30-minute call with a construction security specialist. We review your BEC exposure, CMMC gap, project file server topology, and EDR coverage — at no cost. Written report in 14 days.
Get Free Assessment →
📊
Breach Cost Calculator
Enter your GC size, endpoint count, and project sensitivity. Get an estimated breach cost range with TDPSA notification costs and CoreRecon ROI — in 30 seconds.
Calculate My Exposure →
📞
IR Hotline — On Call Now
Active breach? Ransomware on the project file server? Call (800) 955-2596. 24/7 SOC with construction-sector incident response experience. 30-min response SLA.
Call (800) 955-2596 →
Sources (32): FBI IC3 — Business Email Compromise: The $50 Billion Scam (PSA 2023) • FBI IC3 — 2025 IC3 Annual Report ($20.877B losses) • FBI IC3 — BEC Statistics Page • FBI IC3 — 2024 Annual Report • Eftsure US — "$7.7M fraud: US BEC scams hit construction and government sectors" • ENR — "Justice Served: Scammer Sentenced in Major Construction Payment Fraud" • ReliaQuest — "Ransomware Has Grown 41% for Construction Industry" (Nov 2024) • Preactive IT Solutions — "Ransomware Defense for Construction and Engineering Firms" • Construction Dive — "Tech adoption makes construction industry top target" • Construction Dive — "US construction tech firms brace for increased cyberattacks" • Corvus Insurance — "Cyber Threat Landscape & Digital Threats in the Construction Industry" • IntegrateCyber — "Construction Ransomware Attacks" (Williams Brothers/Akira, Feb 2026) • ransomware.live — Ransomware tracking database • Hunter Strategy — "Ransomware Surge Against Construction Firms" • Rapid7 — "Threat Landscape of the Building and Construction Sector: Ransomware" • The Record from Recorded Future News — "Texas-based oilfield supplier disruptions" • BlueRadius — "Texas Cybersecurity Breach Report 2025: $1.35B Losses" • Procore — "Protecting Your Project Data: Key Cybersecurity Takeaways" • VQIS — "Does Your Construction Software Stack Carry Cybersecurity Risk?" • Reddit r/Construction — "PSA: Procore might be compromised" • Reddit r/ProCore — "What's happening at Procore?" • Texas Attorney General — TDPSA guidance • Texas AG Public Information Act Handbook (2026) • Texas Comptroller — The Public Information Act • Texas Construction Law Blog — "Constructing Compliance: TX Data Privacy and Security Act" • Construction Pros Insurance Services — "Texas Cyber Insurance for Contractors 2026" • LayerLogix — "Cybersecurity Threats for Houston Businesses in 2026" • Brock Insurance Group — "Texas Cyber Risk Management: Practical Playbook" • NorthStar Technology Group — "Supply Chain Cybersecurity for DoD Contractors" • Infonaligy — "CMMC Phase 2: What Texas Contractors Must Do by Nov 2026" • NIST SP 800-171 Rev 2 — csrc.nist.gov • Suffolk County government disclosures, Newsday (Sep 2022) • UK construction press, Royal BAM Group disclosures (early 2020)