ALITEQ.

a construction giant just leaked SSNs, bank accounts, and military project files in one breach

Payouts King says it walked off with 27 terabytes from Turner Construction — including files it claims are covered by U.S. arms-export law. Turner took seven weeks to tell anyone.

Priya NairUpdated 49m ago7 min readWeb story
Construction cranes on a large building site against a city skyline

Turner Construction — the firm that built Yankee Stadium, Salesforce Tower, and defense facilities most of us will never hear the names of — has confirmed a data breach that exposed Social Security numbers, bank account details, dates of birth and passports for at least 6,098 people. A group calling itself Payouts King claims it took a lot more than that: 27.2 terabytes of data, including engineering drawings, contracts and files it says are covered by U.S. arms-export law. Turner has confirmed the personal-data theft. It has not confirmed the military-files claim, and neither have we — that distinction matters, and we'll get to why.

Turner isn't a small contractor. It's one of the largest construction management firms in the U.S., the kind of company that ends up on hospital builds, semiconductor fabs, and government facilities specifically because it can handle contracts requiring security clearance and defense-industry compliance. That's the context that makes this breach different from a typical HR-data leak: if the files Payouts King is describing are real, some are legally required to stay inside U.S. borders and away from foreign nationals under ITAR, the export-control regime that governs defense-related technical data.

How the Turner breach played out

  1. Jul 2, 2026

    Unauthorized access to Turner's systems begins, per the company's own disclosure.

  2. Jul 15, 2026

    The intrusion window closes — Turner says access ended this date.

  3. Jul 24, 2026

    Payouts King posts about an unnamed victim on its leak site, without identifying Turner.

  4. Jul 27, 2026

    Turner confirms internally that files containing personal information were accessed without authorization.

  5. Aug 11, 2026

    Payouts King publicly names Turner Construction and claims 27.2TB of stolen data.

  6. Aug 18, 2026

    Turner reports the breach to the California Attorney General's office.

  7. Aug 21, 2026

    Written notices go out to affected individuals, roughly seven weeks after the intrusion began.

The confirmed exposure covers names, Social Security numbers, dates of birth, salary figures, home addresses and the bank account and routing numbers used for direct deposit; some files also contained passport numbers. At least 38 of the affected individuals are Vermont residents, per that state's separate breach-notification filing, within the broader 6,098-person figure Turner disclosed. For anyone in that group, this isn't 'watch your email' territory — SSN plus bank account plus date of birth is close to the complete kit needed to open new-account fraud in someone else's name.

What's confirmed vs. what's just claimed

Turner Construction (official disclosure)

vs

Payouts King (ransomware group claim)

Not disclosed
Data volume
27.2 terabytes
At least 6,098 notified
People affected
Not specified
SSNs, salaries, bank details, passports, DOB
Data types
Same, plus engineering, contract and military project files
Confirmed via regulatory filing
Verification
Unverified — no third party has confirmed the ITAR file claim
disclosure) wins 1wins 0 claim)
A digital padlock icon over binary code, representing a data breach
Payouts King's 27.2TB claim is unverified — ransomware groups routinely inflate stolen-data figures to pressure victims into paying. · Unsplash

Why the military files matter more than the SSNs

An SSN breach is bad for 6,098 people. If Payouts King's claim about ITAR-protected files is real, this breach is bad for a different reason entirely — export-controlled technical data landing in the wrong hands isn't just a privacy violation, it's the kind of thing that pulls in the State Department, not just a state attorney general filing. We'd treat that claim with real caution even from a source we trusted more: ransomware groups inflate stolen-data figures constantly, because a bigger number is better leverage in an extortion negotiation. We've covered exactly this dynamic before — a group naming a high-profile victim with a dramatic number and zero independent verification. That doesn't mean Payouts King is lying. It means 'a ransomware gang says so' isn't evidence, and neither Turner nor any government agency has confirmed the ITAR portion of this claim as of publication.

What to actually do if you got the letter

1

Enroll in the free IDShield/IDX credit monitoring Turner is offering — the enrollment window closes November 18, 2026.

2

Freeze your credit at all three bureaus (Equifax, Experian, TransUnion) regardless of whether you enroll — it's free and undoes nothing you're currently using.

3

Watch your bank account for direct-deposit redirection attempts specifically — your routing and account number were exposed, not just a card number.

4

Treat any 'HR' or 'payroll' email referencing this breach with extra suspicion; breach notices are exactly what phishing campaigns clone first.

5

If you're a Vermont resident or in another state with its own notification rules, check your state AG's breach filing for details Turner's national notice might not include.

Turner Construction breach FAQ

Is Turner Construction confirming the 27.2TB or military-files claim?
No. Turner has confirmed the personal-data breach and notified affected individuals; it has not corroborated Payouts King's claims about data volume or the ITAR-protected military project files.
How many people are affected?
At least 6,098 individuals were notified, including at least 38 Vermont residents identified in that state's separate breach filing. The total could grow as the investigation continues.
What should I do if I get a notice from Turner?
Enroll in the free credit monitoring, freeze your credit at all three bureaus, and watch bank and payroll-related communications closely — your SSN, bank account and date of birth were exposed together, which is enough for new-account fraud.
Is Payouts King a known ransomware group?
It's a newer name in the ransomware-extortion space, using the now-common pattern of posting an unnamed victim first, then naming them weeks later if a ransom isn't paid — the same pressure tactic seen from other groups this year.

Turner says it's working with outside forensic experts and has reported the breach to California's Attorney General, which is the disclosure trail worth watching for updates — state AG filings tend to get more specific than corporate press statements. Until there's independent confirmation of the ITAR-file claim, the responsible read is: the personal-data breach is real and serious, the national-security angle is a claim from the people extorting Turner, and those are two different levels of certainty. If you handle sensitive data for defense-adjacent clients, this is also a reminder that supply-chain and vendor breaches keep hitting exactly the industries that can least afford them.

Software & Systems Editor

Priya Nair

Priya has daily-driven more Linux distros than she can name and treats her setup like a workshop. She covers the operating systems, apps and settings worth your time — and cheerfully calls out the 'optimizations' that just quietly break your machine.

Work out the hardware

The Aliteq brief

The tech worth knowing — hardware, AI, gaming, deals. No spam, unsubscribe anytime.

Keep reading