← MasTec

2025 MasTec — third-party zero-day breach exposed 25,220 people (June 2026 notices)

2025 25.2K records affected Share on X

Data compromised

Names, dates of birth, addresses, Social Security numbers, financial account details, and some account credentials

Technical writeup

MasTec, Inc., a U.S. infrastructure construction company, reported to the Maine Attorney General that 25,220 individuals were affected by unauthorized network access tied to a zero-day vulnerability in one of its third-party solutions. The company was notified of suspicious activity affecting the vendor solution in October 2025; forensic review concluded in February 2026 that names, dates of birth, addresses, Social Security numbers, financial account details, and some account credentials were compromised. Consumer notification letters were mailed June 5, 2026 per regulator filings.

Root cause

Zero-day vulnerability in a third-party solution; unauthorized network access (suspicious activity noted October 2025)

References