Buford-Thompson Company, LTD Data Breach Exposes Social Security Numbers and Bank Account Data

Published: 1 October 2026
Constructions data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: September 2026

A ransomware group known as Aurora claims to have stolen 1.7 TB of data from Texas construction firm Buford-Thompson Company, LTD, including Social Security numbers for 350+ employees, Frost Bank account details, and donor records from two nonprofits. The company has not publicly confirmed the breach. Affected individuals should place a credit freeze and monitor their accounts immediately.

CompanyBuford-Thompson Company, LTD
IndustryConstructions
Data Types ExposedSocial Security Numbers, Wages and Addresses, Bank Account Numbers and ACH Credentials, Litigation and Legal Files, Construction Bid and Project Data, Donor Personal Information, Accounting and Payroll Files, Personal Financial Records
People Affected350+ individuals
Attack MethodRansomware
Regulators NotifiedNot Publicly Disclosed

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the Buford-Thompson Data Breach?

Buford-Thompson Company, LTD is a Texas-based general contractor with more than 30 years of experience building schools for K-12 districts. A ransomware group calling itself Aurora has claimed responsibility for stealing a massive trove of company data. The group says it obtained roughly 1.707 terabytes of files from the contractor’s systems.

According to the claims made public in September 2026, the stolen dataset includes years of payroll records, banking information, legal files, and construction project data. The attackers say they pulled five years of W-2 tax files, dating from 2021 through 2025. These files reportedly include unencrypted Social Security numbers for more than 350 current and former employees.

Buford-Thompson has not publicly confirmed this incident. As a result, many details about how the attackers gained access remain unknown. There is currently no public statement from the company describing when the intrusion began or how it was discovered.

Because this report stems from a ransomware group’s own leak-site listing, the claims have not been independently verified by the company. However, the specificity of the described files, including bank account numbers and litigation records, suggests the attackers had deep access to internal systems. Readers should treat these claims seriously while the situation develops.

Who was affected?

The population affected by this incident appears to include current and former Buford-Thompson employees. The claimed W-2 files cover more than 350 individuals. This means payroll data spanning half a decade may be at risk.

In addition to employees, the exposure may reach far beyond the construction company itself. The leaked data reportedly includes donor records from Human Services Campus, a Phoenix-based homeless services nonprofit. It also reportedly includes QuickBooks files from Along Side Ministries, a Phoenix prison ministry organization.

Therefore, individuals who never worked for or interacted directly with Buford-Thompson could still be impacted. Donors to these nonprofits may have had their personal and financial details exposed. The number of affected individuals has not been publicly disclosed beyond the employee figure mentioned above.

Because the construction firm works on K-12 school projects across Texas, school districts and their contractors may also face exposure. Subcontractors tied to the 36 or more active projects named in the claims could see sensitive bid and pricing data made public.

What Information Was Potentially Exposed?

The scope of data referenced in the attackers’ claims is unusually broad. It spans employee tax records, corporate banking credentials, litigation files, and third-party nonprofit donor information. Below is a summary of the data categories described.

  • Social Security numbers, wages, and addresses from W-2 tax forms (2021-2025)
  • Attorney-client privileged litigation files from a school district lawsuit
  • Frost Bank account numbers, ACH routing credentials, and line-of-credit agreements
  • Signature cards and monthly bank statements spanning 2022-2026
  • Blueprints, bid estimates, and subcontractor pricing for school construction projects
  • Donor records including names, addresses, phone numbers, emails, and donation amounts
  • QuickBooks accounting and possible payroll files from a nonprofit ministry
  • Personal records belonging to the Thompson family, including insurance, loans, and property documents

This combination of data creates serious identity theft risk. Social Security numbers paired with full names and addresses give criminals nearly everything needed to open fraudulent credit accounts. In addition, the banking credentials described, including account and routing numbers, could enable direct financial fraud if genuine.

Beyond identity theft, this breach carries unusual business and reputational risks. For example, the exposure of bid estimates and subcontractor pricing could let competitors undercut the company on future contracts. Meanwhile, leaked litigation files could compromise the company’s legal position in ongoing disputes. Donors to the affected nonprofits may also face targeted phishing attempts using their donation history.

What is the company doing?

Buford-Thompson has not issued a public statement confirming this breach as of this writing. Because the available information comes from the ransomware group’s own claims, there is no confirmed timeline of the company’s internal response. It is not known whether the company has notified affected employees or regulators.

Consequently, this article cannot describe specific remediation steps, credit monitoring offers, or law enforcement involvement, since none have been disclosed. If the company later confirms the incident, affected individuals should expect formal written notice. That notice would typically explain what data was involved and what protections, if any, are being offered.

In the meantime, affected employees and nonprofit donors should not wait for formal confirmation before taking precautions. Given the sensitivity of the data described, proactive monitoring is a reasonable step regardless of whether the company has spoken publicly yet.

What Should Affected Individuals Do?

Place a Fraud Alert or Credit Freeze

Because Social Security numbers are reportedly part of this exposure, affected individuals should consider placing a fraud alert or credit freeze immediately. A credit freeze blocks new creditors from accessing your credit report. This makes it much harder for criminals to open new accounts in your name.

You can request a freeze for free from each of the three major credit bureaus: Equifax, Experian, and TransUnion. A fraud alert is a lighter-touch option that still requires lenders to verify your identity before extending credit. Either step can meaningfully reduce your risk of becoming an identity theft victim.

Monitor Your Credit Reports and Bank Accounts

Given the alleged exposure of bank account numbers and routing credentials, affected individuals should closely watch their financial accounts. Check statements regularly for unauthorized charges or withdrawals. If you notice anything suspicious, contact your bank immediately.

In addition, request free copies of your credit reports from AnnualCreditReport.com. Review them for unfamiliar accounts or inquiries. Doing this regularly for the next year can help you catch fraud early, before it causes lasting financial damage.

Watch for Phishing and Social Engineering Attempts

Criminals often use stolen personal data to craft convincing phishing emails or phone calls. Because this breach reportedly includes names, addresses, and employer details, scammers may try to impersonate Buford-Thompson, a bank, or a nonprofit you’ve donated to. Be cautious of unexpected messages asking for personal or financial information.

Never click links or provide sensitive details in response to unsolicited contact. Instead, verify requests by calling the organization directly using a number you look up independently. This simple habit can prevent many common identity theft schemes.

Consider Identity Theft Protection Services

Because full Social Security numbers and financial account details are allegedly involved, enrolling in an identity theft monitoring service may provide added peace of mind. These services can alert you to new accounts opened in your name or unusual credit activity. Some also offer identity restoration assistance if fraud occurs.

While no specific service has been publicly announced by Buford-Thompson at this time, affected individuals do not need to wait for an offer. Many reputable monitoring services are available for purchase independently. If the company later provides free monitoring, you can still enroll in it alongside any protections you’ve already set up.

Consult a Data Breach Attorney

Given the scope and sensitivity of the data allegedly exposed, affected individuals may want to speak with a data breach attorney. An attorney can help you understand your legal rights and whether you qualify for compensation. This is especially relevant if your Social Security number or financial data was part of the stolen dataset.

Many attorneys offer free initial case evaluations for data breach victims. As a result, there is little downside to exploring your options. This is particularly worthwhile if you experience financial losses or identity theft linked to this incident.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



Related Data Breaches

View the full list of tracked data breaches →