A ransomware group calling itself Qilin claims to have carried out an attack against Tommer Construction, with the claim surfacing on the group’s dark-web leak site on August 11, 2026. This listing was tracked by ransomware.live, a security research platform that monitors ransomware groups’ public leak sites. At this stage, the claim comes solely from the group itself and has not been independently verified by Tommer Construction, by any regulator, or by an independent third party.
What we know — and don’t
- Qilin listed Tommer Construction on its leak site with a claimed date of August 11, 2026.
- Tommer Construction operates in the construction sector, categorized here as ‘other.’
- The specific types of data the group claims to have obtained have not been disclosed in the listing and remain unconfirmed.
- No public confirmation from Tommer Construction or any regulatory body has been issued regarding this claim as of this writing.
- As with most ransomware leak-site postings, the claim should be treated as unverified until corroborated by the company or official sources.
What should you do if you have an account with this company?
- Change your password for any account associated with Tommer Construction, and avoid reusing that password elsewhere.
- Enable two-factor authentication (2FA) wherever it is offered, particularly on email and financial accounts.
- Be cautious of unexpected emails, texts, or calls referencing this incident — scammers often exploit breach news to run phishing attempts.
- Monitor your bank and credit card statements for unfamiliar activity in the coming weeks.
- Consider signing up for an identity monitoring service like a service like Aura or LifeLock to get alerted if your personal information appears in places it shouldn’t.
- Keep an eye on official communications from Tommer Construction for further updates or guidance.
BreachLetter will update this page if Tommer Construction confirms this incident, if it is reported to regulators, or if new verified information becomes available.