CoreRecon Threat Intelligence  •  Texas Construction & Engineering  •  July 2026 V47

TX Construction & Engineering:
Draw Schedules, CMMC 2.0, Procore Credential Theft, Wire Fraud

Williams Brothers Construction (Houston, Feb 2026) lost data to Akira ransomware. Bouygues Construction took a €10M operational hit from Maze in Jan 2020. A Texas general contractor lost $2.5M in a BEC draw-wire fraud in 2024 (~$776K later recovered through banking-channel reversal). Suffolk County NY faced a 9-month operational outage from AlphV/BlackCat ransomware ($25M+ recovery through insurance). Halliburton TX named incident (Oct 2024) brings CUI implications. TX engineering firm BEC fraud on engineering billing is the smaller-scale version of the same pattern. CMMC 2.0 Phase 2 (Nov 2026) + DFARS 252.204-7012 72-hour disclosure + NIST SP 800-171 Rev 2 (110 controls) + 1 TAC §201 DIR/TxDOT state-funded project IT clauses + TDPSA §541.062 ($7,500/violation) + FTC Safeguards §314 where mortgage/closing flow-down applies. Procore / Autodesk ACC credential theft attack surface. BIM / CAD file server encryption is the most disruptive ransomware payload. 41% construction ransomware surge 2023–2024 (ReliaQuest).

Download the Full Threat Brief — Free
July 2026 CoreRecon Intelligence Report V47 CMMC 2.0 / 32 CFR Part 170 / DFARS / NIST SP 800-171 / DIR/TxDOT / TDPSA 32 Verified Sources
41%
Construction ransomware
surge 2023–2024
(ReliaQuest)
$2.5M
TX GC BEC draw-wire
fraud loss (2024)
~31% partially recoverable
110
NIST SP 800-171
Rev 2 controls
CMMC Level 2 baseline
$89
Sentinel per
endpoint / month
TX-resident SOC
30min
CoreRecon IR SLA
TX-resident SOC
SDVOSB certified
What This Brief Covers

TX Construction &
Engineering Threat Brief

Full intelligence report on the attack surface facing Texas general contractors, engineering firms, and defense-adjacent construction operations — from Williams Brothers Construction (Akira, Feb 2026, Houston) and Bouygues Construction (Maze, €10M, Jan 2020), to TX GC $2.5M BEC draw-wire fraud (2024), Suffolk County NY (AlphV/BlackCat, $25M+ recovery), Halliburton TX (Oct 2024 named incident), BAM Construct UK, and TX engineering firm BEC fraud. Plus the regulatory stack that binds every Texas construction firm: CMMC 2.0 / 32 CFR Part 170 (Phase 2 enforcement begins Nov 2026), DFARS 252.204-7012 72-hour DoD disclosure, NIST SP 800-171 Rev 2 (110 controls), FAR 52.204-21 (15 basic safeguarding), 1 TAC §201 DIR/TxDOT state-funded project IT clauses, TDPSA §541, and FTC Safeguards §314 where mortgage/closing flow-down applies. Coverage built for construction firm owners, controllers, IT leads, project managers, estimators, and DFARS / CMMC program managers at TX general contractors, engineering firms, and defense-adjacent subs.

32 Verified Sources Including:

  • Williams Brothers Construction (Feb 2026) — Akira ransomware affiliate; Houston-based heavy-civil contractor; CUI exposure for MILCON-adjacent scope
  • Bouygues Construction (Jan 2020) — Maze ransomware; €10M impact; multi-month recovery; CYBER insurance renewal signal across EU and US peers
  • TX GC $2.5M BEC draw-wire fraud (2024) — business email compromise on progress-payment; ~$776K recovered; callback SOP absent
  • Suffolk County NY (Dec 2022) — AlphV/BlackCat; 9-month operational disruption; $25M+ recovery through insurance
  • Halliburton TX (Oct 2024) — energy/infrastructure contractor; CMMC implications for defense-adjacent divisions
  • BAM Construct UK (2024) — Voluntis ransomware; European construction sector ENC benchmark
  • CMMC 2.0 (32 CFR Part 170) — Phase 2 enforcement begins Nov 2026; C3PAO assessment readiness required
  • DFARS 252.204-7012 + 7021 — 72-hour DoD DIBNet disclosure on confirmed CUI incidents; SPRS posting baseline
  • NIST SP 800-171 Rev 2 — 110 control families; CMMC Level 2 alignment; DFARS 252.204-7021 SPRS documentation
  • Procore / Autodesk ACC credential theft attack surface; BIM / CAD file server encryption (Revit / AutoCAD / MicroStation)
  • 30/60/90-day hardening checklist with CMMC / DFARS / NIST / DIR / TDPSA control mapping
  • CoreRecon Sentinel / Fortress / Command tier fit for 25–250+ endpoint TX construction / engineering firms

Access the Full Brief

We email it as a PDF attachment. No newsletter. No spam. One delivery.

Submission failed — please try again or email john@corerecon.com

Brief Sent.

Check your inbox — the PDF is on its way. If it lands in spam, drag it to your inbox so you find it later.

Want it immediately? Download below — we already emailed a copy.

Download PDF Now → Book Free Assessment →

Questions before then? Call (800) 955-2596 — live TX SOC, not a call center.

SDVOSB Certified • TX-Based SOC • No offshore data routing
Questions? (800) 955-2596
✅ 32 verified sources
✅ CMMC 2.0 / 32 CFR Part 170 / DFARS / NIST SP 800-171 / DIR/TxDOT / TDPSA covered
✅ 8-section 30/60/90 checklist
✅ TX-specific incidents: Williams Brothers (Akira 2026), Bouygues Maze, TX $2.5M BEC, Halliburton TX
✅ One email delivery, one PDF