Pear Ransomware Hits Metropolitan Construction: NC Contractor Plan

Pear ransomware hit Metropolitan Construction Systems July 24, second July NC-relevant construction attack. NC contractor defense playbook. Call (336) 886-3282.

Cover Image for Pear Ransomware Hits Metropolitan Construction: NC Contractor Plan

TL;DR: DeXpose confirmed on July 24, 2026 that the Pear ransomware crew publicly claimed responsibility for an attack on Metropolitan Construction Systems, a New York City commercial roofing company, with an attack date of July 20 and a full data-leak threat. RedPacket Security confirmed the leak-site posting. This is the fourth NC-relevant construction / manufacturing ransomware event in the last 30 days, following Qilin's July 22 hit on P&A Construction, the July 7 Qilin hit on S.J. Louis Construction, and the July 20 Anubis hit on Bath Fitter. Together they form a documented ransomware wave against US construction and trade contractors. Every North Carolina general contractor, trade contractor, engineering firm, and specialty subcontractor needs to treat July 25, 2026 as the day to audit backups, RMM, and Sage/Foundation/Procore/BIM systems.

Key takeaway: Construction is the third-most-targeted sector in H1 2026, and the attackers know that jobsite technology + estimating databases + owner PII + BIM models + insurance-bond dependencies make construction firms uniquely coercible. The defense stack that works — immutable backup, 24/7 MDR, RMM allowlist, jobsite laptop hardening, ERP segmentation — is well understood; the question is whether it is installed before the leak-site posting or after.

Need a 72-hour construction cybersecurity assessment covering Sage, Foundation, Procore, and jobsite laptops? Contact Preferred Data Corporation at (336) 886-3282. BBB A+ rated, serving High Point, Greensboro, Winston-Salem, Charlotte, Raleigh, and the Piedmont Triad since 1987.

What Happened at Metropolitan Construction Systems and Who Is Pear?

Pear is a mid-2026 ransomware operation that surfaced on public leak sites in the spring and has been building victim volume through the summer. DeXpose's July 24 analysis documents the Metropolitan Construction Systems posting: a threat of full data leak, an attack date of July 20, and public claim July 24. Metropolitan Construction Systems is a New York City commercial roofing contractor — a business profile that maps precisely onto dozens of Triad, Triangle, and Charlotte-area NC commercial roofing and specialty-trades contractors.

Three structural elements of Pear and its peers matter for NC construction owners.

  • Double extortion is standard. Encrypt to halt operations, then threaten to leak stolen data (project plans, owner PII, insurance certificates, subcontractor W-9s, banking details) to increase pressure to pay.
  • Construction is a preferred sector because the operational-tempo cost of downtime is unusually high — a general contractor cannot bid, cannot invoice, and cannot certify pay applications while systems are down, and every day of delay compounds subcontractor and owner friction.
  • Insurance-bond dependencies amplify coercion. A ransomware event that reveals inadequate cybersecurity to a surety, an owner, or a lender can trigger bond reviews, financing covenant violations, or contract termination. Construction firms often pay to avoid the second-order consequences even when the technical damage is contained.

For context, Help Net Security's July 24 mid-year ransomware report documents construction as a top-tier target sector in H1 2026, and multiple 2026 crews (Qilin, Anubis, Pear, Interlock, Gentlemen) all have named US construction victims within the past 60 days.

Why Is Construction Such a Preferred Ransomware Target in 2026?

Construction firms are structurally attractive to ransomware crews for eight overlapping reasons that most business owners have never seen enumerated.

  • Operational-tempo pressure. Ransomware downtime costs a GC or trade contractor in immediate lost billable days, subcontractor idle time, and equipment rental hemorrhage. A three-day outage can permanently damage a schedule.
  • Data-value density. Owner PII, subcontractor tax IDs, banking details, insurance certificates, project financials, competitive bids, BIM models, and engineering IP are all in the same file server. One compromise exposes all of it.
  • ERP + jobsite fragmentation. Sage 300 CRE / Foundation Software / Viewpoint Vista / Procore / Autodesk Construction Cloud / QuickBooks Enterprise / a dozen jobsite laptops running under a single admin — the attack surface is broader than most SMBs.
  • Weak internal IT. Most 25-250 employee NC contractors do not have a full-time internal IT staff; they use a mix of MSP + owner IT + jobsite superintendent hardware ownership, which produces gaps.
  • BYOD jobsite hardware. Contractor and subcontractor personal laptops and tablets connect to office VPN, opening ingress paths the MSP never sees.
  • Owner and surety scrutiny. A ransomware disclosure to owners, sureties, and lenders has second-order commercial consequences that push firms toward paying.
  • Cyber-insurance underinsurance. Contractors are historically underinsured on cyber; a 5-10 employee subcontractor often has zero standalone cyber policy.
  • Multi-tenant MSP concentration. When an MSP is compromised, all downstream contractor tenants can be hit in a single push, per the Anubis/RMM-abuse pattern documented in our July 25 remote-access post.

Each of these can be closed with the right controls. The problem is that most NC construction firms have never assessed themselves against the full list.

Who in North Carolina Is Actually Exposed?

North Carolina construction is a top-10 US market by employment and a major economic engine of the Triad, Triangle, and Charlotte metros. The NC Department of Commerce Labor & Economic Analysis Division reports NC construction employment expanded by roughly 30,000 jobs in 2024-2025, with concentration in the Charlotte, Raleigh-Durham, Greensboro, Winston-Salem, and Wilmington MSAs.

Five NC construction segments are inside the current ransomware wave's target profile.

  • General contractors and construction managers in Charlotte, Raleigh, and the Triad building commercial, healthcare, education, industrial, and multifamily projects, running Sage 300 CRE or Foundation Software with Procore or Autodesk Construction Cloud on top.
  • Civil engineering firms and land developers across NC, particularly those in the Piedmont Triad and Triangle megaregions where infrastructure and mixed-use projects concentrate.
  • Specialty and trade contractors — mechanical, electrical, plumbing, roofing, glazing, flooring, drywall, structural steel — with 25-250 employees and heavy Sage/Foundation/QuickBooks/Procore usage.
  • Design-build and MEP-focused firms where BIM/Revit and coordination models represent significant intellectual property.
  • Public-sector contractors (school districts, DOT, municipal utility construction) subject to public-records disclosure obligations after an incident.

For every one of the above, the July 24 Metropolitan Construction Systems posting is a directly transferable warning.

What Systems Do NC Contractors Need to Harden First?

A 30-day construction cybersecurity hardening plan concentrates on eight systems in order of ransomware value.

  • Construction ERP (Sage 300 CRE, Foundation Software, Viewpoint Vista, QuickBooks Enterprise). Segregate ERP servers to a management VLAN, enforce phishing-resistant MFA on all admin accounts, apply vendor patches within 14 days, enable audit logging with SIEM ingestion.
  • Project management and BIM (Procore, Autodesk Construction Cloud, Bluebeam, Revit, Navisworks). Enforce SSO with conditional access, restrict external-share permissions, monitor for unusual bulk-download activity, back up cloud-project artifacts to an independent immutable store.
  • File servers and document management. Immutable snapshots on the primary NAS (Synology, QNAP, Windows Server + Veeam Hardened Repo), documented restore test in the last 90 days.
  • Email (Microsoft 365 or Google Workspace). Enable phishing-resistant MFA (FIDO2, Windows Hello for Business) for all owners, PMs, and estimators. Configure DMARC to reject to prevent vendor-impersonation invoice fraud. Enable anti-BEC controls in Defender for Office 365 or Google Workspace Advanced Protection.
  • VPN and remote access. Retire or patch legacy Citrix, SonicWall SMA, or Fortinet VPN appliances; migrate to ZTNA (Cloudflare Access, Zscaler ZPA, Twingate, Netskope) for smaller firms. Force-invalidate all sessions after CVE-required patches.
  • RMM tools and jump hosts. Enumerate every installed RMM agent on every endpoint; allowlist only the sanctioned agent; alert on any RMM install from any other source. This is the specific defense against the Anubis/RMM playbook.
  • Jobsite laptops and mobile devices. MDM enrollment (Intune, Kandji, Jamf), disk encryption, tamper protection, EDR, application allowlisting, and a documented offboarding process that revokes access same-day.
  • Backup and disaster recovery. Immutable, air-gapped backups with a documented 24-hour restore test in the last 90 days. Backup infrastructure isolated from the primary domain; backup admin accounts on a separate identity plane.

Executed together, these controls interrupt the Pear / Qilin / Anubis kill chain at multiple points. Executed piecemeal, they leave the gap that gets exploited.

What Does the Cost Look Like for an NC Contractor?

Honest cost for a 50-employee NC general contractor to implement the full stack is $60,000-$150,000 in year one and $45,000-$120,000 recurring. That is meaningful money, and it is small relative to the median construction-ransomware total cost.

LayerYear-1 Cost (50 seats)Year-2+ RecurringFit for Small NC Contractor
Immutable backup + tested restore$8-25K$6-18KTable stakes
24/7 MDR + third-party EDR$18-55K$16-50KTable stakes
KEV-cadence patching (managed IT baseline)$18-40K$15-35KTable stakes
Phishing-resistant MFA + RMM allowlist$6-18K$3-10KPriority
Sage/Foundation/Procore hardening + segmentation$6-20K$2-10KPriority
Cyber-insurance evidence packet + IR tabletop$4-12K$2-8KPriority
Total (all six)$60-170K$44-131KDelivered by internal IT or MSP

Sophos' 2026 State of Ransomware report puts median SMB total-cost-of-recovery above $1M when downtime, restoration, notification, insurance retention, and lost sales are included. For a construction firm with additional bond, financing, and owner-relationship exposure, the total cost is typically higher.

Ready to size the 30-day construction hardening plan? Contact Preferred Data Corporation at (336) 886-3282 or visit 1208 Eastchester Drive, Suite 131, High Point, NC 27265. PDC managed IT for construction covers Sage, Foundation, Procore, jobsite laptops, and 24/7 MDR.

How Does a Ransomware Event Intersect With Owner Contracts, Sureties, and NC ITPA?

A construction ransomware event is a five-front event, and none of the fronts wait patiently. Four intersections matter for NC contractors specifically.

  • Owner contracts. Most commercial construction contracts (AIA A102/A201, ConsensusDocs) include cybersecurity, breach-notification, and data-handling clauses. A breach may trigger owner notification within 24-72 hours and expose the contractor to contract termination or set-off rights on pay applications.
  • Sureties and lenders. Bond capacity reviews and lender covenant compliance can be affected by cyber incidents. A material incident may need to be disclosed at annual bond renewal or on loan compliance certificates.
  • NC Identity Theft Protection Act (N.C.G.S. § 75-65). NC ITPA notification covers exfiltrated employee W-2 data, subcontractor W-9 data (if the sole proprietor's SSN is on file), and any owner PII touched by the incident. Notification is triggered by the theft, not the encryption.
  • Cyber insurance. 2026 renewals almost universally require documented MFA and EDR, per the 96%/88% mandate coverage. A construction firm that files a claim without documented controls faces coverage disputes.

The safe posture is a documented cybersecurity program, a documented incident-response plan with owner-notification templates, and a pre-negotiated retainer with an IR firm before the incident.

Frequently Asked Questions

Are ransomware crews really targeting mid-size construction firms specifically?

Yes. Manufacturing and construction together are the two most-attacked sectors in H1 2026 per Help Net Security. Named US construction ransomware victims in the past 60 days include P&A Construction, S.J. Louis Construction, Metropolitan Construction Systems, and several others across GC, civil, and specialty-trade segments. The attackers understand the operational-tempo pressure.

We are a 12-person specialty trade subcontractor. Are we in scope for these attacks?

Yes, though the ransomware value is typically extracted through supply-chain pivot rather than direct encryption. A subcontractor with weak controls can be used as a vector into a GC's Procore, Autodesk, or Sage system, at which point the GC becomes the primary victim. GCs have started asking subcontractors for cybersecurity attestations for exactly this reason.

Does our general liability or builder's risk insurance cover ransomware?

Generally no. General liability, builder's risk, and inland-marine policies specifically exclude cyber. A standalone cyber policy is required. Verify with your broker before an incident, not after.

How long can a construction firm survive without ERP access after a ransomware event?

Sophos 2026 data and construction-specific IR case studies suggest that firms with tested restore can be operational in 3-5 days; firms without tested restore average 2-4 weeks of degraded operations. For a small GC with tight cash-flow tied to monthly pay applications, 2-4 weeks is existential.

What is the single highest-value first control we should install this week?

Immutable, air-gapped backup with a documented restore test in the last 90 days. Every other control is secondary because without a real backup, negotiation posture collapses. If you already have this, add 24/7 MDR.

Should we pay if we are hit?

The industry answer is "do not pay" and the honest answer is "it depends and it is a legal and insurance decision." Payment does not guarantee decryption, does not guarantee data return, does not stop future extortion, and (in specific cases involving sanctioned entities) can trigger OFAC violations. The decision requires legal counsel, an experienced IR firm, and the insurance carrier at the same table.

How does Pear compare to Qilin, Anubis, or Interlock?

Pear is a smaller, newer crew. Qilin is a top-volume operator with multi-platform malware; Anubis is US SMB-focused with heavy RMM-abuse; Interlock has hit US nonprofits and mid-market entities. Defensive controls are similar across all four: immutable backup, MDR, KEV patching, RMM allowlist, ERP segmentation.

Where do we start if we have no existing cybersecurity program?

Start with three things simultaneously: (1) immutable backup and restore test, (2) 24/7 MDR on all endpoints, (3) phishing-resistant MFA for owners and finance staff. Then run a tabletop exercise. Everything else follows from those.

Support