By Charles Swihart, Founder and CEO of Preactive IT Solutions, November 21, 2025 The construction and engineering sectors continue to face escalating cybersecurity risks in late 2025, with ransomware and supply chain vulnerabilities emerging as dominant threats. Recent reports from government agencies, cybersecurity researchers, and industry surveys highlight a surge in targeted attacks that disrupt […] The post Breaking Cybersecurity Threats Targeting the Construction Industry: November 2025 Update appeared first on TechBullion.By Charles Swihart, Founder and CEO of Preactive IT Solutions, November 21, 2025 The construction and engineering sectors continue to face escalating cybersecurity risks in late 2025, with ransomware and supply chain vulnerabilities emerging as dominant threats. Recent reports from government agencies, cybersecurity researchers, and industry surveys highlight a surge in targeted attacks that disrupt […] The post Breaking Cybersecurity Threats Targeting the Construction Industry: November 2025 Update appeared first on TechBullion.

Breaking Cybersecurity Threats Targeting the Construction Industry: November 2025 Update

2025/11/29 15:00
4 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

By Charles Swihart, Founder and CEO of Preactive IT Solutions,

November 21, 2025

The construction and engineering sectors continue to face escalating cybersecurity risks in late 2025, with ransomware and supply chain vulnerabilities emerging as dominant threats. Recent reports from government agencies, cybersecurity researchers, and industry surveys highlight a surge in targeted attacks that disrupt operations, compromise sensitive project data, and exploit interconnected IT/OT environments and third-party relationships.

Construction firms—often managing complex projects with subcontractors, suppliers, and digital tools like Building Information Modeling (BIM) and IoT devices—are particularly vulnerable. These attacks go beyond data theft, frequently halting on-site operations, delaying timelines, and inflating costs. Below are the most critical developments from November 2025.

1. Akira Ransomware Group Intensifies Attacks on Construction and Engineering

The Akira ransomware operation remains one of the most active threats to critical infrastructure, with construction and engineering consistently ranking among its top-targeted sectors.

  • On November 13, 2025, the FBI, CISA, and international partners released an updated joint advisory on Akira, revealing evolved tactics including faster encryption variants (Akira_v2) and new command-and-control tools like Ngrok and SystemBC malware.
    • Google Threat Intelligence and other sources note manufacturing, legal/professional services, and construction/engineering as the most impacted industries, with a noticeable uptick in construction victims in recent months.
  • Initial access frequently exploits vulnerabilities in edge devices (e.g., SonicWall VPNs via CVE-2024-40766) or compromised credentials on systems lacking multi-factor authentication (MFA). Akira has claimed over $244 million in ransom payments as of late 2025, primarily from small- to medium-sized businesses but increasingly from larger organizations.

This persistence underscores why construction sites, with remote access needs and legacy systems, are prime targets.

2. OT/ICS Incidents Highlight Detection-Recovery Gaps and Remote Access Risks

The SANS Institute’s 2025 State of ICS/OT Cybersecurity Report, released in November 2025 and sponsored by OPSWAT, surveyed hundreds of industrial professionals and revealed persistent challenges in converged IT/OT environments everyday in construction and heavy industry:

  • 21.5% of organizations reported an ICS/OT cybersecurity incident in the past year.
  • 40% of those incidents caused operational disruption, while nearly 20% required over a month for full recovery—despite almost half being detected within 24 hours.
  • Unauthorized remote external access was the leading incident vector (around 50% of cases), yet only 13% of organizations have implemented advanced controls like session recording or real-time approvals for remote connections.

These findings align with broader trends: regulated entities experience similar incident rates but far fewer safety or financial impacts thanks to stronger controls.

3. Supply Chain and Third-Party Attacks Escalate

Attackers increasingly exploit the fragmented vendor ecosystems inherent to construction projects:

  • Supply chain compromises allow entry through weaker partners. A notable example from September 2025 involved the Volvo Group (a major construction equipment manufacturer), which was hit by a ransomware attack on third-party HR software provider Miljödata, exposing employee data across multiple organizations.
  • The ongoing “TamperedChef” malvertising campaign, detailed in November 2025 reports from Acronis and others, distributes trojanized installers for everyday tools (e.g., PDF editors, manual readers). It disproportionately affects healthcare, construction, and manufacturing due to frequent searches for specialized equipment documentation. Signed with abused certificates, these installers establish remote access and persistence.

Broader 2025 data from Dragos, Honeywell, and others show that ransomware incidents in industrial sectors (including construction) are rising sharply, with supply chain and remote access as the primary entry points.

Why Construction Firms Must Act Now

These threats are not abstract: a successful breach can encrypt project files, disrupt equipment controls, leak bids or blueprints, or halt job sites for weeks. The financial and reputational damage often far exceeds ransom demands.

Construction leaders should prioritize:

  • Enforcing MFA everywhere, especially on VPNs and remote access tools.
  • Segmenting IT/OT networks and deploying ICS-aware monitoring.
  • Vetting third-party vendors rigorously and requiring cyber incident notification clauses.
  • Testing incident response plans with tabletop exercises focused on ransomware and supply chain scenarios.
  • Investing in threat intelligence tailored to ICS/OT environments.

As the industry continues to digitize in 2026, cybersecurity is no longer optional—it’s a core component of project delivery and risk management.

Charles Swihart has over 30 years of experience in IT and cybersecurity, is the author of the Amazon best-selling book “On Thin Ice,” and was named MSP Titan of the Industry in 2024 for leadership in construction and engineering IT services.

Comments
Market Opportunity
SURGE Logo
SURGE Price(SURGE)
$0.006768
$0.006768$0.006768
-20.18%
USD
SURGE (SURGE) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Franklin Templeton CEO Dismisses 50bps Rate Cut Ahead FOMC

Franklin Templeton CEO Dismisses 50bps Rate Cut Ahead FOMC

The post Franklin Templeton CEO Dismisses 50bps Rate Cut Ahead FOMC appeared on BitcoinEthereumNews.com. Franklin Templeton CEO Jenny Johnson has weighed in on whether the Federal Reserve should make a 25 basis points (bps) Fed rate cut or 50 bps cut. This comes ahead of the Fed decision today at today’s FOMC meeting, with the market pricing in a 25 bps cut. Bitcoin and the broader crypto market are currently trading flat ahead of the rate cut decision. Franklin Templeton CEO Weighs In On Potential FOMC Decision In a CNBC interview, Jenny Johnson said that she expects the Fed to make a 25 bps cut today instead of a 50 bps cut. She acknowledged the jobs data, which suggested that the labor market is weakening. However, she noted that this data is backward-looking, indicating that it doesn’t show the current state of the economy. She alluded to the wage growth, which she remarked is an indication of a robust labor market. She added that retail sales are up and that consumers are still spending, despite inflation being sticky at 3%, which makes a case for why the FOMC should opt against a 50-basis-point Fed rate cut. In line with this, the Franklin Templeton CEO said that she would go with a 25 bps rate cut if she were Jerome Powell. She remarked that the Fed still has the October and December FOMC meetings to make further cuts if the incoming data warrants it. Johnson also asserted that the data show a robust economy. However, she noted that there can’t be an argument for no Fed rate cut since Powell already signaled at Jackson Hole that they were likely to lower interest rates at this meeting due to concerns over a weakening labor market. Notably, her comment comes as experts argue for both sides on why the Fed should make a 25 bps cut or…
Share
BitcoinEthereumNews2025/09/18 00:36
Melania Trump humiliated her husband as he tries to outrun his decay: analysts

Melania Trump humiliated her husband as he tries to outrun his decay: analysts

First lady Melania Trump just handed President Donald Trump his biggest humiliation yet as the president tried to outrun his decay, according to two political analysts
Share
Rawstory2026/05/05 11:42
Peter Brandt Agrees: This COT Shift Could Be Bitcoin’s Biggest Bull Signal Since 2025

Peter Brandt Agrees: This COT Shift Could Be Bitcoin’s Biggest Bull Signal Since 2025

Peter Brandt backs a rare COT positioning flip in Bitcoin futures. McClellan says large specs turned net long with urgency. Is a rally coming? Three strikes. That
Share
LiveBitcoinNews2026/05/05 11:30

Starter Gold Rush: Win $2,500!

Starter Gold Rush: Win $2,500!Starter Gold Rush: Win $2,500!

Start your first trade & capture every Alpha move