On July 22, 2026, the Qilin ransomware group listed P & A Construction on their leak site, claiming to have exfiltrated internal files. This information is based on reports from ransomware tracking sites and has not been officially confirmed by the company or a regulator.
Only "internal files" have been mentioned as exposed data types; there is no confirmation of specific data types such as SSNs, medical, or financial data. The number of affected individuals remains unconfirmed and unquantified in the available sources. No specific states affected have been identified.
As of the current reporting, no official breach notification letter or company statement has been issued. There are no indications of an Attorney General filing, active class action lawsuits, or Multi-District Litigation (MDL) related to this incident.