2025 MasTec — third-party zero-day breach exposed 25,220 people (June 2026 notices)
Data compromised
Names, dates of birth, addresses, Social Security numbers, financial account details, and some account credentials
Technical writeup
MasTec, Inc., a U.S. infrastructure construction company, reported to the Maine Attorney General that 25,220 individuals were affected by unauthorized network access tied to a zero-day vulnerability in one of its third-party solutions. The company was notified of suspicious activity affecting the vendor solution in October 2025; forensic review concluded in February 2026 that names, dates of birth, addresses, Social Security numbers, financial account details, and some account credentials were compromised. Consumer notification letters were mailed June 5, 2026 per regulator filings.
Root cause
Zero-day vulnerability in a third-party solution; unauthorized network access (suspicious activity noted October 2025)