The Cherokee Group, a US-based construction company, reportedly suffered a ransomware attack by the Akira group, discovered on February 20, 2026. This information originates from ransomware monitoring sites that indexed public threat actor posts.
The exfiltrated data reportedly includes employee personal documents such as passports and driver's licenses, as well as corporate financial data, project data, drawings, specifications, and NDAs. The specific number of affected individuals and whether Social Security Numbers were exposed have not been publicly confirmed. No official breach notifications or company statements are currently available.
Details are still emerging, and additional information has not yet been disclosed by The Cherokee Group. Notifications to affected individuals, if required, may be delayed.