ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Kiewit discloses data breach affecting employees and contractors after email account compromise

Kiewit Corp., a major construction and engineering firm operating across the transportation, power, water, mining, oil and gas, and building sectors in the United States, Canada and Mexico, has notified current and former employees and independent contractors that their personal information may have been compromised in a data breach.


The Omaha-based company identified unauthorized access to an employee’s Microsoft 365 account and moved to contain the intrusion by resetting passwords and disabling the compromised account. Kiewit also brought in outside digital forensics specialists and alerted law enforcement as part of its response.


A subsequent internal review to identify which individuals and what data had been affected wrapped up on July 24, 2026. Information that may have been exposed includes full names, home addresses, dates of birth, Social Security numbers, driver’s license numbers or other government-issued identification, and health information tied to employment. Not every affected person had all of these data categories compromised.


Kiewit informed the Massachusetts Office of Consumer Affairs and Business Regulation of the breach on Aug. 26, 2026, and began mailing notification letters to affected individuals on Aug. 21, 2026.


To help mitigate potential harm, Kiewit is providing complimentary identity theft protection and credit monitoring through IDX, covering a period of 12 to 24 months depending on the individual. Those services are not automatic and must be activated by the affected person to take effect. Enrollment is available through the IDX sign-up portal or by calling 1-833-788-9712, with an activation deadline of Nov. 21, 2026.


The company has also set up a call center dedicated to fielding questions about the incident and the support resources on offer. It can be reached at the same number, 1-833-788-9712, and operates Monday through Friday from 9 a.m. to 9 p.m. Eastern time, excluding holidays.


Separately, the law firm Edelson Lechtzin LLP said it is examining potential data privacy claims tied to the breach. The firm, which describes itself as a national class action practice, said it is evaluating whether Kiewit met its obligations to safeguard sensitive employee and contractor information and is offering free case assessments to individuals who received a breach notification. The firm characterized its inquiry as ongoing and said affected individuals could face heightened exposure to identity theft and financial fraud given the categories of data involved, including Social Security numbers, driver’s license numbers and health records.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543