Congressional Iron Works Data Breach Exposes Social Security Numbers and Passport Numbers

Published: 1 September 2026
Manufacturing data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: Not Publicly Disclosed

Congressional Iron Works, a Baltimore-Washington area metals contractor, suffered a ransomware attack by the Akira group, which claims to have stolen 35GB of data including Social Security numbers, passport numbers, driver’s licenses, financial records, and health information belonging to employees and clients. The number of people affected has not been disclosed. Affected individuals should monitor their credit reports and consider a credit freeze immediately.

CompanyCongressional Iron Works
IndustryManufacturing
Data Types ExposedSocial Security Numbers, Passport Numbers, Driver’s License Numbers, Financial Information, Health Information, Client Information, Company Financial Records, Non-Disclosure Agreements
People AffectedNot Publicly Disclosed
Attack MethodRansomware
Regulators NotifiedNot Publicly Disclosed

What Happened in the Congressional Iron Works Data Breach?

Congressional Iron Works, a metals contractor serving the commercial construction industry in the Baltimore-Washington region, has confirmed a serious cybersecurity incident. A ransomware group known as Akira has claimed responsibility for breaching the company’s network. The group says it accessed and copied roughly 35 gigabytes of corporate data before threatening to publish it online.

According to the threat actor’s own claims, the stolen files include sensitive employee records. This reportedly covers passport numbers, Social Security numbers, driver’s license numbers, financial information, and health information. The attackers also claim to hold client records, company financial documents, project files, and signed non-disclosure agreements.

The breach discovery date has not been publicly disclosed. As a result, the exact timeline between initial intrusion and detection remains unclear. This is a common pattern with Akira-linked attacks, which often involve extended, quiet access to networks before extortion demands surface.

Because Akira is a known ransomware-as-a-service operation, the group typically pairs data theft with extortion threats rather than only encrypting systems. In response, forensic investigators are generally brought in to determine the scope of the intrusion, confirm which systems were touched, and assess whether the stolen data matches what the attackers claim. Congressional Iron Works has not yet released detailed findings from any such review.

Who was affected?

The breach appears to affect current and former employees of Congressional Iron Works, based on the personal data categories the attackers listed. In addition, the company’s clients may also be affected, since client information was reportedly included in the stolen files.

The exact number of individuals affected has not been publicly disclosed. Therefore, it isn’t yet clear whether this incident involves dozens, hundreds, or more people. Given that Congressional Iron Works has operated since 2004 as a specialty metals contractor, the affected population likely includes tradespeople, office staff, and business partners tied to commercial construction projects across the Baltimore-Washington area.

What Information Was Potentially Exposed?

The threat actor’s claims point to a wide range of sensitive personal and business data. Because this incident involves both employee and client records, the potential exposure spans multiple categories of highly sensitive information.

  • Social Security numbers
  • Passport numbers
  • Driver’s license numbers
  • Financial information
  • Health information
  • Client information
  • Company financial records
  • Project documentation
  • Non-disclosure agreements

If confirmed, this combination of data creates serious risk. Social Security numbers, passport numbers, and driver’s license numbers together form what’s often called a full identity kit. This means criminals could use this data to open new credit accounts, file fraudulent tax returns, or apply for loans in someone else’s name.

Health information adds another layer of concern. Medical data can be used for insurance fraud or to craft convincing phishing messages that reference real treatment details. Meanwhile, financial information exposure raises the risk of direct account takeover or unauthorized charges. Because passport numbers were reportedly included, affected individuals may also face risks tied to international identity fraud or travel document misuse.

What is the company doing?

Congressional Iron Works has not publicly released a detailed statement outlining its full response. However, incidents involving ransomware groups like Akira typically prompt companies to engage cybersecurity forensic teams immediately. This helps determine which systems were compromised and whether the attackers’ claims about stolen data are accurate.

In addition, companies facing this type of extortion attempt often work to strengthen network defenses, reset credentials, and isolate affected systems to prevent further access. Formal written notifications to affected employees and clients typically follow once the scope of the breach is confirmed. At this time, specific details about credit monitoring or identity protection services offered by Congressional Iron Works have not been publicly disclosed.

What Should Affected Individuals Do?

Monitor Your Credit Reports

Affected individuals should check their credit reports regularly for unfamiliar accounts or inquiries. You can request free credit reports from all three major bureaus at AnnualCreditReport.com.

Because Social Security numbers were reportedly exposed, this step matters even more. Fraudulent accounts can sometimes take months to surface, so reviewing your reports every few weeks over the coming year is a reasonable precaution.

Consider a Credit Freeze or Fraud Alert

Given the reported exposure of Social Security numbers and financial data, placing a credit freeze with each bureau is a strong protective step. A freeze blocks new creditors from accessing your file, which makes it much harder for identity thieves to open accounts in your name.

Alternatively, a fraud alert requires lenders to verify your identity before extending credit. This option is less restrictive than a freeze but still adds a meaningful layer of protection. Either way, acting sooner rather than later reduces your window of exposure.

Protect Against Passport and Government ID Fraud

Because passport numbers may have been exposed, affected individuals should watch for signs of misuse tied to travel documents. If you notice unusual activity related to your identity abroad or receive unexpected government correspondence, report it immediately.

In addition, consider contacting the U.S. State Department if you suspect your passport information has been misused. Replacing a passport can be a hassle, but it’s a reasonable step if you have clear evidence of fraud tied to this breach.

Stay Alert for Phishing and Scam Attempts

Because health, financial, and personal information may have been exposed, scammers could use these details to craft convincing phishing emails or phone calls. Be cautious of any message asking you to verify personal information or click a suspicious link.

As a rule, legitimate companies rarely ask for sensitive details through unsolicited emails or texts. If you receive a message referencing this breach, verify it directly with Congressional Iron Works using contact information from its official website, not links provided in the message itself.

Consult a Data Breach Attorney

Given the sensitivity of the data involved, affected individuals may want to speak with a data breach attorney. An attorney can help you understand whether you qualify for compensation and what steps to take next.

Many attorneys offer free case evaluations for situations like this. This means you can explore your legal options without any upfront cost, which is worth considering given the scope of personal information reportedly involved in this incident.



Related Data Breaches

Browse all recent data breaches →