The Turner Construction breach: payroll files, and what to do about it

Somebody spent two weeks in Turner’s systems in July and left with human-resources paperwork: Social Security numbers, dates of birth, home addresses, what people earn and the accounts their pay lands in. Letters went out from 18 August. Here is what the notice says, what it leaves out, and the three steps that actually match this data.

ByNikita Lushpanov· Chief Product Officer ·LinkedIn
Quick answer

Someone was inside Turner Construction’s systems between 2 and 15 July 2026. Turner confirmed on 27 July that files with personal information had been accessed, filed with the attorneys general of California and Vermont on 18 August, and began posting notices the same week. The exposed fields are Social Security numbers, dates of birth, home addresses, salary information and the bank account details used for direct deposit, with passport numbers possibly in some files. The people affected are current and former personnel rather than customers, and no nationwide total has been published. Freeze your credit file at all three bureaus, tell your bank the deposit account is in a breach, and request an IRS Identity Protection PIN before the filing season, on top of the five years of identity protection the letter offers.

What the notice says, point by point

Everything below comes from Turner’s notification, its filings with the California and Vermont attorneys general on 18 August 2026, and the reporting that followed between 19 and 24 August. Where the company has not said something, the row says so rather than filling the gap.

QuestionWhat is statedWhat that means
When the intruders were inside2 to 15 July 2026That window comes from Turner’s own investigation. The company has not said how they got in, and unlike several other breaches this summer it has not described a phishing call or a stolen password.
When Turner knewConfirmed on 27 July 2026That is the date Turner says it established that files holding personal information had been accessed without authorisation. Working out whose data was in them took another three weeks, which is the normal shape of these investigations rather than a delay.
What was in the filesSocial Security numbers (Social Insurance numbers in Canada), dates of birth, home addresses, salary information and the bank account details used for direct deposit. Some files may also have held passport numbers.This is the notification’s own list, and it is an unusually complete one. Most breach notices stop at a name and a Social Security number; this set adds what you earn and the account your pay lands in.
How many people6,098 in the California filing, 38 in the Vermont filingBoth were filed on 18 August 2026. Those are state filings rather than a national count, and Turner has not published a total. For a contractor that operates across the US and Canada, the real number is very likely higher.
Whose recordsCurrent and former personnelPayroll and HR paperwork is what this data set is, so the people written to are staff past and present rather than clients or homeowners. Turner began posting written notices on or about 18 August.
What Turner is offeringFive years of identity protection at no costProvided through IDX or IDShield depending on which version of the notice arrived, with identity-theft insurance and recovery support included. The enrolment deadline printed on the notice is 18 November 2026, and none of it starts until you activate it with the code in your letter.
Who claims responsibilityA ransomware crew calling itself Payouts KingIt posted about an unnamed victim on 24 July and named Turner on 11 August, claiming 27.2 terabytes covering engineering drawings, ITAR-restricted and military project files, litigation records, contracts and NDAs alongside the employee data. None of that volume has been verified by anyone outside the group. Turner’s response was that it “does not comment on claims made by criminal organizations”.

Sources: Turner’s notification letter and its California and Vermont attorney-general filings of 18 August 2026, plus reporting by Construction Dive and the consumer and legal press, 19–24 August 2026. The 27.2-terabyte figure and the description of engineering and military documents come from the group claiming the attack and have not been confirmed by Turner or by anyone who has examined the data.

1. What happened, in order

Somebody had access to systems at Turner Construction, the largest general contractor in the United States, between 2 and 15 July 2026. Turner established on 27 July that files containing personal information had been opened without authorisation, and spent the following three weeks working out whose. A crew calling itself Payouts King posted about an unnamed victim on 24 July and named Turner on 11 August. The filings with the attorneys general of California and Vermont went in on 18 August, written notices to affected people started going out on or about the same day, and the story reached the trade and legal press between 19 and 21 August. Turner has published no separate public statement beyond the notice and a short line declining to discuss the attackers’ claims.

2. Why this one lands on employees rather than customers

A contractor’s customers are developers, hospitals, airports and public agencies, and none of them hand over a Social Security number to get a building put up. The individuals in a company like this are the people who work for it, so the file that was taken is payroll and human-resources paperwork rather than a customer database. That changes who is exposed and how they find out. There is no account to log into, no place to type your name and see whether you are on a list, and no way to check yourself. The letter is the mechanism, it goes to the address Turner last had for you, and former staff are the group most likely to miss it.

3. What was taken, and why this list is worse than most

The notification lists Social Security numbers for US personnel and Social Insurance numbers for Canadian personnel, dates of birth, home addresses, salary information and the bank account details used for direct deposit, with passport numbers possibly present in some files. Set that beside the average breach notice, which stops at a name and an email address. Everything here is permanent or slow to change: a Social Security number is issued once, a date of birth never moves, and while a bank account can be closed it is not something you do on a Tuesday afternoon. What is missing is equally worth noting. There are no passwords in this set and nothing to reset, so the account-security routine that follows a normal breach does not apply.

4. Three steps that match this particular data set

Most breach advice is generic because most breaches are. This one is specific enough to answer field by field. Because a Social Security number came out, freeze your credit file at Equifax, Experian and TransUnion, each separately and free, which blocks a new account rather than reporting one after it opens. Because the direct deposit account number came out, tell your bank the details are circulating and ask what it can add to the account, and ask payroll to verify any change of deposit instructions through a channel that is not email. Because your salary and Social Security number are now in the same file, request an Identity Protection PIN from the IRS before the filing season opens, which stops a return being filed in your name using income figures that look right.

5. The rest of the week’s list

Enrol in the identity protection Turner is paying for, using the code printed on your letter. Five years is a longer offer than most companies make, and the deadline on the notice is 18 November 2026, after which it cannot be activated. Check your Social Security earnings record for employment you did not do, which is where somebody using your number to work shows up. Read your bank statements rather than filing them, because a small test transaction is often the first sign an account is being probed. And keep the letter along with the date it arrived, since anything that comes of this later is far easier to pursue with the paperwork in hand. Our guide to breach notification letters goes through what a real one contains, line by line.

6. The calls and messages that follow

Anyone holding this file can open a conversation with your full name, your address, your date of birth, where you work and what you are paid. That is more than a bank asks before it believes you are you, and it is why the messages that follow a payroll breach tend to work. Expect calls about the breach itself, offers to “verify your enrolment” in the monitoring, and emails about a payroll or tax problem that quotes a real figure at you. Accuracy is the trap here, because most people check whether a message knows them rather than how it reached them. Assume every detail in that list is known, and verify by hanging up and calling a number you already had.

7. The lawyer emails, and what they actually mean

Within a few days of the disclosure, law firms were publishing investigations and sites were collecting names of affected people. That stage is worth understanding before you hand anything over. A firm announcing an investigation is looking for clients; there is no certified class, no court has approved anything, and no money exists to be claimed. If a case is filed and eventually settles, notice comes from a court-appointed administrator, arrives by post and costs nothing to act on, and that process runs for years. Our list of settlements currently taking claims is checked against the official administrator sites, so you can see what the real stage looks like.

8. The part that outlives this incident

The credit monitoring runs out in five years and the file at Turner gets closed long before that. What does not change is the home address and phone number that made the stolen record usable in the first place, both of which are published and sold by people-search and data-broker sites regardless of who gets breached next. Taking those listings down is the one step here with an effect that outlasts the news, and it needs repeating rather than doing once, because brokers rebuild profiles from public records within weeks. For the general version of the response, our post-breach guide covers it in seven steps.

The address in that file is also for sale

A stolen Social Security number becomes usable when it sits next to a current address and phone number, and those are published by 499 broker and people-search sites whether or not anyone breaches anything. PersProtect finds where you are listed, files the removals and keeps checking that they stay down. The scan is free.

Check my exposure — free →
Common questions

The Turner breach, answered

I worked on a Turner site years ago. Could I be in this?

Possibly, and that is the awkward part of a payroll breach. What was taken is the paperwork an employer keeps, and employers keep it long after somebody leaves, because tax and payroll records have retention periods measured in years. Turner’s notice covers current and former personnel rather than a date range you can check yourself. The letter is the only confirmation, and it goes to the last address on file, which is a problem if you have moved since. Nothing from this incident has been published as a searchable set of records, so no breach-checking tool can answer it either, ours included.

My bank account number was in it. Can someone take money out?

Not directly with the number alone, but that is not the risk worth worrying about. An account number plus a routing number is what payroll uses to send money in, and the realistic attack is somebody contacting Turner or a benefits administrator pretending to be you and changing where your pay goes. That is called payroll diversion, and it is the most common thing done with a set like this. Tell your bank the details are in a breach and ask what they can add to the account, and if you are still employed, ask payroll to confirm any change of deposit details by a channel other than email.

Does the salary information matter, or is it just embarrassing?

It matters more than people expect. Knowing what you earn is what lets a caller open with something only your employer should know, which is most of the work in sounding legitimate. It also feeds tax fraud: someone filing a return in your name does better when the income figures look plausible, and here they have your real salary, your Social Security number and your date of birth in the same file. That is the combination the IRS Identity Protection PIN exists for.

What is the single most useful thing to do?

Freeze your credit file at Equifax, Experian and TransUnion. It is free, takes about ten minutes per bureau online, and it stops a new account being opened in your name instead of telling you afterwards that one was. Take the five years of identity protection in the letter too, because it is paid for and it catches what a freeze does not, but do not let the offer stand in for the freeze. A freeze is lifted temporarily whenever you apply for credit yourself.

A passport number may have been in my file. Is that worth acting on?

Turner’s notice says only that some files may have contained one, so the first thing to establish is whether yours did. If it did, a passport number on its own does not let anyone travel, because the document itself is what gets checked at a border. What it does is add another convincing identity detail to the pile, and it is one you cannot change without replacing the document. There is no central place to freeze it. Treat it as one more reason to be suspicious of anyone who quotes your details back at you.

Should I join a class action?

There is nothing to join yet. Several firms announced investigations within days of the disclosure, and an investigation is a firm looking for people to represent, not a filed case and not money waiting to be claimed. If a case is filed and eventually settles, the notice reaches you through a court-appointed administrator, usually by post, and claiming is free. Anything arriving now that wants a fee, your bank details or your Social Security number to register a claim is a scam built on the news.

What about the military project files the attackers claim to have?

That claim comes from the group offering the data, and nobody outside it has verified any of it. It is a real consideration for Turner and for the agencies it builds for, and it is not something an individual employee can act on. If your name is attached to project documents rather than payroll records, the useful step is to tell your current employer and let the security and legal side of it be handled there. For your own exposure, the payroll fields are the part that reaches you personally.

I got an email about the Turner breach. Is it real?

Treat it as suspicious. Turner notified people by post from around 18 August, and press coverage of a breach with Social Security numbers and bank details in it is exactly what a phishing wave feeds on. Judge a message by how it reached you rather than by how it reads, because the wording and the logo are the easy part to copy. A genuine notice explains what happened and how to enrol in the monitoring; it never asks you to send back your Social Security number, and it has no reason to want your online banking login.

You cannot reissue a Social Security number

You can take down the address, phone number and relatives that make it usable. See which sites publish yours right now — free, in about a minute.

Run my free exposure scan →