← Blog

MasTec Breach: 25K Exposed via Third-Party Zero-Day Flaw

Share on X

U.S. infrastructure contractor MasTec, Inc. disclosed a breach affecting 25,220 individuals after suspicious activity in a third-party solution was investigated from October 2025 through February 2026. Notification letters went out June 5, 2026.

What was exposed

  • Names, dates of birth, and addresses
  • Social Security numbers
  • Financial account details and some account credentials

Action items

  1. Freeze or monitor credit if you received a MasTec notice.
  2. Rotate passwords on any work or vendor portals tied to MasTec projects.
  3. Report suspicious payroll or benefits verification calls citing real SSN fragments.

Canonical record: MasTec 2025 third-party breach on BreachHistory.

Sources: Maine AG, ClassAction.org