Were you recently affected by a data breach?

Kiewit Data Breach

Kiewit Corporation notified current and former employees and contractors that unauthorized access to an employee email account may have exposed names, Social Security numbers, driver’s license numbers, and employment-related health information.

Kiewit
Date of Breach: Review completed July 24, 2026; notice issued August 21, 2026
CAU logo

Who was affected:

Clients of Kiewit

Impacted Data:

Names, addresses, dates of birth, Social Security numbers, driver’s license or other government-issued identification numbers, and health information related to employment

Kiewit Corporation, a major construction and engineering firm headquartered in Omaha, Nebraska, recently notified current and former employees and independent contractors that their personal information may have been exposed after unauthorized access to an employee email account. Companies that collect and store sensitive employment and identification records are responsible for keeping that information secure, and when a breach occurs, those affected deserve a clear explanation of what happened and what they can do to protect themselves.

Kiewit’s Data Breach Investigation

Kiewit Corporation reported that it detected unauthorized access to an employee’s Microsoft 365 email account. Once the activity was discovered, the company said it moved quickly to contain the incident, forcing a password reset on the affected account and disabling it to prevent further access. Kiewit also stated that it launched an internal investigation, engaged outside counsel, retained a third-party digital forensics firm, and notified law enforcement of the incident. According to the notice, Kiewit then performed a comprehensive review of the compromised account to identify which individuals may have had personal information exposed, a process the company said was completed on July 24, 2026. Based on that review, Kiewit determined that certain personal information belonging to current and former employees and independent contractors may have been contained in the account. As of the date of the notice, the company said it was not aware of any actual misuse of the affected information.

Incidents like this one, where an attacker gains access to a single employee email account, are a common way that sensitive workforce data ends up exposed, because corporate inboxes frequently contain years of accumulated human resources records, benefits paperwork, tax documents, and other files containing employees’ Social Security numbers, driver’s license numbers, and health information. A single compromised mailbox can therefore expose far more personal data than the size of the underlying intrusion might initially suggest, which is part of why a full forensic review is typically required before a company can determine the scope of who was actually affected.

Kiewit’s notice, dated August 21, 2026, was issued after the internal review concluded in late July 2026, reflecting the multi-week gap that is typical between the discovery of a network intrusion and the point at which a company can confidently identify and notify every individual whose information was involved. State data breach notification laws generally require this kind of review to be completed and notice to be sent within a specific window once the scope of an incident is understood, which is why the timeline between initial detection and final consumer notification can often stretch to weeks or months for a large organization with a substantial workforce.

The specific combination of data reportedly involved in this incident, names paired with Social Security numbers, driver’s license or other government-issued identification numbers, and health information tied to employment, is especially valuable to identity thieves. This type of data can be used to open new lines of credit, file fraudulent tax returns, submit false unemployment claims, or attempt medical identity theft, and unlike a stolen credit card number, a Social Security number or driver’s license number cannot simply be canceled and reissued. Individuals who receive notice of this incident are encouraged to take the protective steps outlined below promptly rather than waiting for evidence of misuse to appear, since fraudulent activity stemming from a stolen Social Security number can sometimes surface months or even years after the underlying breach.

Large construction and engineering companies like Kiewit typically maintain years of accumulated payroll, benefits, and identification records for thousands of current and former employees and contractors across many job sites, which makes their internal systems an attractive target for attackers seeking a large volume of sensitive personal data in a single intrusion. Offering complimentary credit monitoring and identity theft protection, as Kiewit has done here, is a standard industry response intended to give affected individuals an early warning if their information is misused, though monitoring alone does not undo the exposure or guarantee that fraud will be caught before damage occurs.

When Did This Breach Occur?

Kiewit’s notice does not specify the exact date on which the unauthorized access to the employee email account first occurred or was first detected. The company stated that its review of the incident to identify affected individuals was completed on July 24, 2026, and that notification letters to affected individuals were dated August 21, 2026. As is common with breaches involving a compromised email account, the underlying intrusion may have occurred earlier than the date the review concluded, since identifying every individual whose data was contained in the account can take considerable time.

What Information Was Breached?

According to Kiewit’s notice, the personal information that may have been involved includes names, addresses, dates of birth, Social Security numbers, driver’s license numbers or other government-issued identification numbers, and health information received in connection with the affected individual’s employment. Kiewit noted that not all of these data elements were involved for every individual affected, meaning the exact combination of exposed information may vary from person to person depending on what was contained in the compromised email account.

What You Can Do

Kiewit is offering complimentary identity theft protection and credit monitoring services through IDX to individuals affected by this incident, with an enrollment deadline of November 21, 2026. Affected individuals should enroll in this monitoring as soon as possible and consider taking the following additional steps:

  • Carefully review bank and credit card statements for any unfamiliar charges
  • Request a free copy of your credit report from each of the three major credit bureaus
  • Consider placing a fraud alert or a security freeze on your credit file
  • Monitor for unexpected tax filings or unemployment claims made in your name
  • Report any suspected identity theft to your state Attorney General and the Federal Trade Commission

File a Data Breach Lawsuit Against Kiewit

If you received a notice from Kiewit Corporation about this data breach, you may have legal options available to you. Companies that hold sensitive employee and personal information have a responsibility to protect it, and when that information is exposed, affected individuals may be entitled to compensation.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: June 16 - July 8, 2026 (discovered July 8, 2026)
Date of Breach: June 17-22, 2026 (discovered June 22, 2026)
Date of Breach: Review completed July 24, 2026; notice issued August 21, 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.