TL;DR: On July 22, 2026, the Qilin ransomware group publicly claimed a cyberattack against P&A Construction, a US civil engineering and general contracting firm, threatening to leak stolen data if no ransom is paid. It is Qilin's third major construction victim in two weeks, part of a 500+ victim year that has made Qilin the most active ransomware brand of 2026 and construction the fastest-growing target vertical in the country. North Carolina's active general contractor base, from Charlotte data-center builders to Raleigh life-sciences firms to Piedmont Triad plant contractors, is next in line.
Key takeaway: Construction firms are being systematically hunted. A single mid-project encryption event on a Charlotte data-center job or a Toyota Battery site build can freeze pay applications, halt subcontractor scheduling, and trigger $100,000 to $500,000 per day in liquidated damages. Sixty focused days of defensive work costs less than one bad afternoon.
Worried you look like the next P&A Construction? Contact Preferred Data Corporation at (336) 886-3282 for a construction-focused ransomware readiness assessment. Serving general contractors, civil engineers, and specialty trades across High Point, Greensboro, Charlotte, Raleigh, Wilmington, and the Piedmont Triad since 1987.
What happened to P&A Construction on July 22, 2026?
On July 22, 2026, the Qilin ransomware group posted P&A Construction (paconst.com) to its dark-web data-leak site, claiming to have breached and exfiltrated firm data and threatening publication if negotiations do not begin. The DeXpose incident brief and coverage on Malware News confirm the listing, describing P&A as a leading US civil engineering and general contracting firm now exposed to standard Qilin double-extortion pressure.
The listing lands during the busiest Qilin week of the year. Per Ransomware.live's Qilin tracker, Qilin is the number-one ransomware brand by posted victims in 2026, with construction, manufacturing, and industrial services heavily represented. On July 9 alone, Qilin claimed S.J. Louis Construction, another US national GC. Precision Steel Services and Italian industrial firm BiesSse landed on leak sites in the same window. P&A is the newest addition to a cluster impossible to dismiss as random.
Why is Qilin the ransomware brand construction firms need to know?
Qilin (also known as Agenda) has been operating as a ransomware-as-a-service program since 2022, and in 2026 it has become the dominant brand in the industry, running neck-and-neck with a rival called Gentlemen for the top spot on nearly every threat-intelligence leaderboard. Comparitech's 2026 ransomware statistics tracker documents more than 500 claimed Qilin victims year-to-date, with construction and engineering in the top three most-hit sectors alongside healthcare and manufacturing.
The MoxFive 2026 Qilin defense guide documents a consistent playbook. Initial access typically arrives through RDP or WinRM brute force, unpatched ProxyShell or ProxyLogon on Exchange, or phishing against project managers and estimators. Lateral movement runs on native PowerShell and Impacket, which sail past legacy antivirus. Exfiltration uses Rclone to push data to attacker-controlled cloud storage before the encryption payload fires, so by the time your Sage 300 CRE server is down, the pay-application data is already for sale.
Why are US general contractors and civil engineering firms so attractive to ransomware crews?
Construction is the fastest-growing ransomware target vertical in the United States in 2026, and the reasons are structural. Per Comparitech, construction ransomware claims are up sharply year-over-year, and threat reports from BlackFog and MoxFive echo the trend. An $80M-revenue GC on 20 concurrent jobs has more moving pieces, more subcontractor identities, and more schedule pressure than a similarly sized professional-services firm, and every one of those factors makes payment more likely.
Five structural attributes make GCs and civil engineers a bullseye:
- Sprawling jobsite networks with weak segmentation. Field trailers, jobsite Wi-Fi, and LTE or Starlink links all touch the same corporate identity plane.
- High-value bid, estimating, and design data. Pay applications, competitive bids, geotechnical reports, and CAD drawings are exactly the documents that make extortion pressure work.
- Subcontractor supply chain sprawl. A typical NCDOT prime carries 40 to 200 subcontractor identities in Procore or Sage, any of which can be a phishing beachhead.
- Schedule pressure that makes payment more likely. A crew that hits mid-pour on a Charlotte data-center foundation knows the owner is exposed to enormous daily standby costs.
- Insurance and compliance are behind the curve. Most Builder's Risk and General Liability programs do not cover ransomware, and few contractors have carried real cyber policies through more than two renewal cycles.
What does a ransomware outage day actually cost a Charlotte or Triangle general contractor?
The direct cost of one lost project day, before ransom is even discussed, ranges from tens of thousands of dollars on a small commercial job to over half a million on heavy civil or data-center work. Charlotte's data-center gold rush, RTP life-sciences construction, the Piedmont Triad's Toyota Battery, Wolfspeed, and Boom Supersonic projects, and Wilmington coastal infrastructure all sit at the top of that range because the owner's daily exposure flows straight to the prime.
The table below is a conservative planning framework based on data from Comparitech and the FBI IC3 Ransomware overview. Actual numbers vary by contract, liquidated-damages clauses, and CCIP or OCIP terms.
| Project type | Typical NC example | Daily standby / liquidated damages exposure | Additional recovery cost per event |
|---|---|---|---|
| Small commercial GC | Single-story build in Winston-Salem or Asheville | $10,000 to $40,000 | $150,000 to $400,000 |
| Multifamily / mid-rise | Apartment stack in Greensboro or Fayetteville | $25,000 to $100,000 | $350,000 to $900,000 |
| Life-sciences / advanced manufacturing | RTP lab fit-out, Toyota Battery contractor | $75,000 to $250,000 | $600,000 to $1.8M |
| Heavy civil / DOT | NCDOT bridge or interchange work | $50,000 to $200,000 | $500,000 to $1.5M |
| Data center | Charlotte or Maiden hyperscaler build | $150,000 to $500,000+ | $1M to $3M+ |
Those numbers do not include the ransom itself, typically $250,000 to several million for a mid-sized construction firm, nor the reputational cost with owners who will remember it at the next prequalification cycle.
Where are the entry points in a typical NC contractor network?
Entry points are predictable, well-documented, and mostly fixable. Post-mortems from MoxFive, the CISA StopRansomware program, and the FBI IC3 all point at the same short list, and most NC contractors have at least three exposed today.
- Exposed RDP and legacy remote access. Superintendents connect back to the office with Remote Desktop accounts protected only by a shared password. Qilin affiliates buy these credentials in bulk on criminal marketplaces.
- Unpatched Microsoft Exchange (ProxyShell / ProxyLogon). A shocking number of small GCs still run on-premise or hybrid Exchange with unpatched public-facing OWA.
- Sage 300 CRE, Foundation, or Viewpoint servers with flat network access. Accounting and PM servers are usually joined to the same domain as every jobsite laptop, with no segmentation.
- Jobsite Wi-Fi on consumer-grade routers. Field trailers in Fayetteville or coastal Wilmington often run a $99 router with default credentials, giving an attacker on the site a foothold into the corporate identity plane.
- Subcontractor accounts in Procore, Sage, or shared drives. A single compromised sub account can exfiltrate every drawing, contract, and pay app on the project.
- Personal email and consumer file-sharing habits. Estimators forwarding bids to Gmail or Dropbox is a phishing lure and a data-leak pathway in one.
What is the 60-day NC construction ransomware defense plan?
Sixty days is enough for a mid-sized GC to close the biggest gaps Qilin and peers actually exploit. This plan follows the CISA StopRansomware guidance and MoxFive's 2026 Qilin defense recommendations, sequenced for how a real NC construction shop can deploy them.
- Week 1 to 2: Shut down external RDP, exposed Exchange, and shared credential vaults. Every remote-access path gets inventoried. Anything not behind MFA and a modern gateway gets closed. Legacy Exchange gets migrated or hardened immediately.
- Week 2 to 3: Deploy phishing-resistant MFA on every identity that touches Sage, Foundation, Viewpoint, Procore, or Microsoft 365. Authenticator apps or FIDO2 keys, conditional access on jobsite devices, no exceptions for owners.
- Week 3 to 4: Deploy modern EDR/MDR across every endpoint and server. Legacy antivirus does not stop Qilin's PowerShell and Impacket tooling. Pair EDR with 24/7 SOC monitoring so a 2:14 AM alert actually gets a response.
- Week 4 to 5: Segment the network. Corporate accounting, estimating file shares, domain controllers, and jobsite trailers belong in separate zones. Field VLANs get internet only, not lateral access.
- Week 5 to 6: Immutable, offsite, tested backups. Object-lock storage, off-domain credentials, and a real restore drill inside the 60-day window. Ransomware crews hunt and delete online backups first.
- Week 6 to 7: Subcontractor and vendor access review. Every third-party identity in Procore, Sage, and shared drives gets reviewed. Dormant accounts disabled, broad drive access scoped down.
- Week 7 to 8: Incident response tabletop with legal, insurance, and executive leadership. Rehearse the first four hours: how to notify the owner, reach counsel, preserve evidence, and trigger the cyber policy. Print the runbook, store copies offline.
A managed IT partner with construction experience executes this plan alongside internal IT rather than replacing it. A managed cybersecurity engagement covers the monitoring layer, and modern backup and disaster recovery handles the immutable-backup requirement.
Want a second set of eyes on the plan? Reach Preferred Data Corporation at (336) 886-3282 for a construction-specific defense review. On-site anywhere within 200 miles of High Point, NC.
What controls will your cyber insurer, GC prequalification packet, and owner CCIP audit require in 2026?
By late 2026, cyber underwriters, general contractor prequalification packets, and owner-controlled insurance programs (CCIP/OCIP) are all asking for evidence of the same short list of controls. Per underwriter guidance summarized by Comparitech and CISA, the questionnaire has shifted from box-checking to evidence-based. Renewing a cyber policy without documented answers now routinely results in higher premiums, lower limits, or non-renewal.
| Control area | What underwriters and owners now require | How Qilin defeats firms that skip it |
|---|---|---|
| Phishing-resistant MFA | On every identity, including admins and service accounts | Buys credentials on criminal markets, logs in cleanly |
| Endpoint detection and response | Monitored EDR/MDR across servers and endpoints | Runs PowerShell and Impacket past legacy AV |
| Patch management SLA | 14-day patch cadence for critical CVEs | Exploits ProxyShell/ProxyLogon on unpatched Exchange |
| Immutable, offsite backups | Object-lock or air-gapped, tested restores | Deletes online backups first, then encrypts |
| Network segmentation | Jobsite, corporate, and accounting isolated | Moves laterally from jobsite trailer to accounting server |
| Incident response plan | Documented, rehearsed, legal counsel identified | Adds ransom pressure while defenders scramble |
| Vendor / subcontractor identity governance | Reviewed quarterly, scoped access | Uses compromised sub account as beachhead |
Firms bidding on defense-adjacent work also face CMMC requirements. Firms holding NCDOT prequalification, working for the University of North Carolina system, or sitting on hyperscaler data-center prime lists are increasingly seeing these same questions in prequal packages.
Frequently Asked Questions
We are a subcontractor, not a general contractor. Are we still a target?
Yes, often more so. Qilin specifically hunts for subcontractor accounts because they provide beachhead access into larger primes. A 30-person sub in Greensboro with legitimate Procore access to a Toyota Battery jobsite is arguably a higher-value target than the prime, because security is weaker and access is nearly the same.
Our project management is in Procore or Sage cloud. Are we protected?
Cloud hosting shifts risk but does not remove it. The MoxFive Qilin defense guide documents multiple 2026 incidents where the entry point was a phished cloud identity, not the platform. Your tenant is only as secure as the Microsoft 365 or Google identities that log into it.
We have on-premise construction accounting. Does that make us safer?
No, usually less safe. On-premise Sage 300 CRE, Foundation, and Viewpoint servers sit inside flat corporate networks with weak segmentation and often skip patch cycles a SaaS vendor ships automatically. On-premise can be secured with real network segmentation and monitoring, but the default posture is worse.
Our jobsite laptops go through Starlink or LTE. How do we protect field devices?
Modern zero-trust remote access replaces "field laptop connects home to a flat network." Combined with EDR, phishing-resistant MFA, and conditional access that checks device health, a Starlink trailer in Wilmington or a super's laptop in Asheville can be as secure as the office. Consumer jobsite Wi-Fi routers, however, must go.
We got prequalified with a General Liability and Builder's Risk carrier. Is that the same as cyber insurance?
No. General Liability, Builder's Risk, and Professional Liability programs almost universally exclude cyber. Coverage for ransomware, extortion, business interruption, and breach response requires a dedicated cyber policy, and in 2026 that policy requires documented evidence of the controls listed above before it will bind.
Do public-works contracts (NCDOT, municipal) require cyber controls?
Increasingly, yes. NCDOT and larger NC municipal owners are adopting language requiring contractors to demonstrate cybersecurity controls, incident-reporting timelines, and subcontractor flow-down. Federally funded projects pull in stricter frameworks, and DIB-adjacent work triggers CMMC-aligned controls.
What is the difference between Qilin, LockBit, and BlackCat as an incident-response scenario?
From a defender's view in 2026, the differences are mostly cosmetic. All three are ransomware-as-a-service programs running double extortion and relying on the same short list of entry points. The prevention and recovery playbook is nearly identical, which is why CISA's StopRansomware guidance is brand-agnostic.
If we get hit mid-project, should we pay?
That decision is legal, insurance-driven, and case-specific, not one to make in the moment. FBI guidance generally discourages payment, and OFAC sanctions rules can make payment to certain groups illegal. Your cyber carrier and outside counsel need to be on the phone within hours; the best predictor of not paying is having tested, immutable backups and a rehearsed IR plan before the incident.