Arban & Carosi, a U.S. construction company, was reportedly targeted in a ransomware attack by the incransom group on April 30, 2026. The incident allegedly resulted in the exfiltration of 1 TB of data. This data is claimed to include employee names, positions, personal and work email addresses, phone numbers, financial documents such as contracts, invoices, and revenue data, customer contact details, project details, internal correspondence, and building plans, including references to U.S. Army buildings.
The number of affected individuals and the specific U.S. states impacted by this incident have not been publicly confirmed. While financial documents were allegedly compromised, there is no verified information regarding the exposure of bank account numbers, social security numbers, or payment card data. Official breach notifications from Arban & Carosi or regulatory filings have not been identified.
Details surrounding the incident, including the full scope of the data compromise, may emerge over time, and official notices to affected individuals may be delayed.