Western Builder

Dedicated to the people who make our built environment better and safer. We tell your stories and celebrate your successes.

Register with us and receive industry news and content only available to subscribers.

Subscribe
Contacts

Indianapolis, IN, USA (HQ)

903 E. Ohio St., Indianapolis, IN 46202

Call: (317) 423-2325

info@acppubs.com
August 2025

Foil the Rise of Cybercriminals

by: Mark Wooditch and Kirk Chamberlain, HUB International
Mark Wooditch, LAOC Construction Practice Leader, HUB International
Mark Wooditch, LAOC Construction Practice Leader, HUB International
Kirk Chamberlain, National Construction Practice Leader, HUB International
Kirk Chamberlain, National Construction Practice Leader, HUB International

The construction industry, long perceived as a hands-on and analog sector, has undergone rapid digital transformation in recent years. With the adoption of Building Information Modeling, drones, robotics, Internet of Things (IoT) devices, and cloud-based project management systems, today’s construction companies are deeply reliant on technology and data. This digital expansion has introduced new vulnerabilities, making the construction sector an increasingly attractive target for cybercriminals.

Project owners are also at risk. Multiple phishing and social engineering-related claims have been reported detailing examples of owners receiving fraudulent emails, allegedly from their contractors, advising new contract payment remittance bank coordinates — only to find those transferred funds disappear forever.

Recent statistics underscore the rising threat. Nationally, the construction sector ranks among the top industry targets, with an average of 226 incidents per year, according to one survey.

The financial impact is equally alarming. According to Verizon’s Data Breach Investigations Report, the average cost of a data breach for small businesses ranges from $120,000 to $1.24 million. These costs include not only ransom payments but also legal fees, regulatory fines, lost business, and reputational damage.

Why Cybersecurity Is a Growing Risk

Several factors contribute to the construction industry’s vulnerability, including:

  • Insufficient preparedness — Many construction companies surveyed admit they have not prioritized cybersecurity and have faced an attack.
  • Widespread technology adoption — From automated site sensors to AI-driven scheduling tools, construction technology expands the attack surface.
  • Valuable data storage — Construction firms routinely store sensitive information, such as proprietary designs, financial data, and confidential government project plans, making them lucrative targets.
  • Third-party risks — Construction projects often involve complex webs of subcontractors, suppliers, and vendors, each introducing additional cybersecurity exposures.

Given these realities, cybersecurity is no longer optional for construction companies — it is essential for operational resilience and project success.

Five Types of Cyberattacks

Understanding the specific types of cyber threats targeting the construction industry is critical for building an effective defense. Common attacks include:

Ransomware
In a ransomware attack, cybercriminals infiltrate company systems, encrypt files, and demand a ransom for the decryption key. The implications extend beyond financial losses. Projects can be delayed, supply chains disrupted, and critical project data exposed. In some cases, missed deadlines due to cyber incidents have led to penalties, lawsuits, and loss of future contracts.

The construction industry is particularly vulnerable because project schedules are tight, and companies may feel pressured to pay ransoms quickly to resume operations. Moreover, smaller firms often lack robust backup systems, making recovery without payment difficult.

Phishing
Phishing remains a major entry point for many cyberattacks. Emails designed to look like legitimate communications lure recipients into clicking malicious links, downloading malware, or revealing login credentials. Many breaches include some form of involvement by company workers through phishing, behavior manipulation, etc., making it one of the most financially devastating forms of cybercrime.

Construction companies are particularly vulnerable because of the fast-paced, collaborative nature of project management, where dozens of people interact across multiple platforms daily.

Data Theft
Construction companies manage a wealth of confidential information, including bid strategies, design documents, intellectual property, and financial accounts. Cybercriminals recognize the value of this data and often sell it on dark web marketplaces or use it for corporate espionage.

Social Engineering
Social engineering tactics — where attackers manipulate individuals into divulging confidential information — are frequently used to gain initial access. Once inside, attackers can quietly siphon off sensitive data over time without immediate detection.

Fraudulent Funds Transfer
Also known as business email compromise (BEC) or electronic payment fraud, fraudulent funds transfer scams are particularly damaging to construction companies, which routinely move large sums for project costs and vendor payments.

Attackers impersonate executives, vendors, or clients to trick employees into transferring funds to fraudulent accounts. These attacks often involve carefully crafted emails or phone calls designed to create urgency or fear. Without proper verification protocols, even vigilant employees can be deceived, resulting in substantial financial losses.

Best Practices to Strengthen Cybersecurity

While the threats are formidable, construction firms can take concrete steps to protect their digital assets and reduce their cyber risk exposure. Here are eight best practices to mitigate cyber risks:

1. Implement Multi-Factor Authentication
Multi-factor authentication (MFA) adds an extra layer of security, requiring users to provide multiple forms of verification before accessing systems or sensitive information. MFA should be mandatory for: