# AECOM listed as Metaencryptor ransomware victim

Published: 2026-09-17 · Severity: high · Sectors: infrastructure
Canonical: https://vorant.io/reports/6d82a5e2-ade2-5b69-ac3c-3b838730caeb/aecom-listed-as-metaencryptor-ransomware-victim

> Ransomware.live reports AECOM as a claimed victim of the Metaencryptor ransomware group, with limited technical detail provided.

This entry from ransomware.live documents a claim by the Metaencryptor ransomware operation that engineering and infrastructure firm AECOM was compromised. The listing itself contains no technical indicators, exploited vulnerability, or intrusion details — it reports aggregate figures (compromised employees, users, and third-party credentials) drawn from underlying leak-site data and infostealer telemetry sponsored by Hudson Rock, but does not disclose the stolen data or attack chain.

For defenders, this is a victim notification rather than a technical advisory: there is no confirmed initial access vector, malware sample, or IOC set published. Organizations with relationships to AECOM (subcontractors, joint ventures, shared infrastructure projects) should monitor for potential downstream exposure of shared credentials or third-party data, and treat the infostealer-to-ransomware pipeline referenced by the sponsor as a general reminder to monitor for credential-stealer infections across the employee and vendor base, since such infections are a common ransomware precursor.

## Mentioned in this report

- Threat actors: metaencryptor
- Malware: Metaencryptor

Source reporting: https://www.ransomware.live/id/QUVDT01AbWV0YWVuY3J5cHRvcg==

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/6d82a5e2-ade2-5b69-ac3c-3b838730caeb/aecom-listed-as-metaencryptor-ransomware-victim.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
