Qilin Ransomware Claims Another US Construction Target as SharePoint Exploitation Raises a Wider Alarm + Video

Listen to this Post

Featured Image

A New Ransomware Warning Emerges

Ransomware attacks rarely arrive as isolated technical incidents. They are part of a broader criminal ecosystem in which attackers continuously search for weak points, steal access, encrypt business systems, and pressure victims into paying for recovery. The latest claim involving Tommer Construction in the United States highlights that continuing threat, while a separate warning surrounding Microsoft SharePoint shows how quickly a software vulnerability can become a doorway into an organization’s wider network.

According to a cybersecurity post published on August 11, 2026, the Qilin ransomware operation allegedly targeted Tommer Construction, encrypting critical files and disrupting normal operations while demanding payment for restoration. The claim comes from a social-media account that attributed the information to hendryadrian.com. At the time of writing, however, independent confirmation of the specific Tommer Construction incident is limited.

That distinction matters. Ransomware groups and threat-monitoring accounts frequently publish claims before victims or security researchers publicly confirm them. A listing or social-media post can therefore be an early warning, but it should not automatically be treated as proof that an intrusion occurred exactly as described.

At the same time, the second claim in the source material is considerably easier to verify. CVE-2026-45659, a high-severity Microsoft SharePoint vulnerability, has been confirmed as actively exploited and has been added to CISA’s Known Exploited Vulnerabilities catalog. CISA has warned that attackers are targeting vulnerable, internet-accessible on-premises SharePoint servers.

National Vulnerability Database

+1

The combination creates an uncomfortable picture for organizations: ransomware groups do not necessarily need a spectacular zero-day to get inside. A neglected server, an exposed application, stolen credentials, or a vulnerability that remains unpatched can be enough to begin a much larger compromise.

Qilin’s Expanding Ransomware Pressure

Qilin has become one of the most recognizable names in the ransomware landscape, operating as a ransomware-as-a-service ecosystem in which affiliates can conduct intrusions while leveraging the group’s encryption and extortion infrastructure.

The alleged Tommer Construction incident follows a familiar ransomware pattern: obtain access, disrupt critical systems, encrypt files, and then demand money in exchange for restoration or other concessions.

The reported target is a U.S. construction company. Public records show that Tommer Construction Company is an established construction business based in Ephrata, Washington, with operations involving road construction, land clearing, land leveling, bridge construction, structural concrete, heavy hauling, and other heavy-equipment activities.

tommerconstruction.com

+1

That makes the ransomware claim particularly relevant from an operational perspective.

Construction companies increasingly depend on digital systems for project documentation, payroll, accounting, procurement, engineering files, scheduling, communications, equipment management, contracts, and interactions with customers and subcontractors.

When those systems become unavailable, the damage can extend far beyond computers.

Why Construction Companies Are Attractive Targets

Construction organizations can present an attractive combination for financially motivated attackers.

They often manage large numbers of employees, subcontractors, suppliers, customers, external partners, cloud services, remote connections, and project files.

The result is a complicated digital environment in which security controls can vary significantly from one system to another.

A ransomware operator does not necessarily need to compromise the most sophisticated system in the company. Finding one poorly protected endpoint, exposed service, reused password, compromised account, or vulnerable server may be sufficient to begin moving deeper into the environment.

The operational consequences can also be significant.

A construction company experiencing a serious ransomware incident could potentially face interruptions involving project management, invoicing, payroll, purchasing, scheduling, document access, communications, and administrative operations.

Even when physical construction work continues, the business infrastructure supporting that work may become severely impaired.

The Tommer Construction Claim Remains Unconfirmed

The most important editorial caution in this story concerns the alleged Qilin attack itself.

The supplied source states that Qilin hit Tommer Construction, encrypted critical files, disrupted operations, and demanded a ransom. However, searches of publicly available sources did not produce an independent confirmation from Tommer Construction, law enforcement, a major cybersecurity vendor, or another authoritative incident-response source.

That means the incident should currently be described as an alleged or claimed ransomware attack, rather than an independently verified breach.

This is particularly important because ransomware leak sites and social-media accounts can contain incomplete, exaggerated, outdated, or otherwise unverified claims.

The underlying company is real, however. Tommer

tommerconstruction.com

+1

The distinction between “the company exists” and “the ransomware attack has been confirmed” is critical.

One is supported by public records.

The other still requires additional evidence.

The More Serious Verified Threat: Microsoft SharePoint

While the Tommer Construction allegation remains uncertain, the Microsoft SharePoint threat referenced in the same source is real and significant.

CVE-2026-45659 is a vulnerability involving the deserialization of untrusted data in Microsoft SharePoint. NIST records the vulnerability with a CVSS 3.1 score of 8.8, placing it in the high-severity category.

National Vulnerability Database

More importantly, this is not simply a theoretical vulnerability.

CISA added CVE-2026-45659 to its Known Exploited Vulnerabilities catalog on July 1, 2026, explicitly identifying active exploitation.

National Vulnerability Database

CISA later warned that threat actors were exploiting multiple SharePoint vulnerabilities to gain unauthorized access to on-premises SharePoint servers and conduct post-exploitation activity.

That included activity involving remote code execution, theft of IIS machine keys, persistence, and malware deployment.

GovDelivery

What CVE-2026-45659 Actually Means

The vulnerability affects on-premises Microsoft SharePoint Server installations.

According to NIST, the vulnerability can allow an authorized attacker to execute code over a network through exploitation of unsafe deserialization. The affected versions include SharePoint Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition versions below Microsoft’s specified fixed builds.

National Vulnerability Database

The authentication requirement should not create a false sense of safety.

Security advisories indicate that exploitation can be performed by an attacker with relatively low-level authenticated access. That means an attacker who has already obtained a legitimate account or otherwise gained the necessary access could potentially turn that foothold into remote code execution.

This is exactly the type of vulnerability that becomes especially dangerous when combined with credential theft.

An attacker does not always need to break through the front door.

Sometimes the attacker steals a key first.

CISA’s Warning Changes the Risk Calculation

There is a major difference between a newly disclosed vulnerability and a vulnerability that has already entered CISA’s Known Exploited Vulnerabilities catalog.

The KEV designation means organizations should treat exploitation as an active security concern rather than a theoretical future possibility.

CISA’s July warning specifically stated that threat actors were exploiting CVE-2026-45659 and other SharePoint vulnerabilities against on-premises systems. It also recommended reducing unnecessary internet exposure and implementing additional security controls around SharePoint infrastructure.

GovDelivery

For defenders, this changes the question.

The question is no longer:

“Could someone exploit this?”

The question becomes:

“Has someone already tried?”

The Ransomware Connection Is More Complicated

The source material connects the SharePoint vulnerability with ransomware activity, but that connection should be handled carefully.

CVE-2026-45659 is unquestionably being exploited.

Ransomware groups unquestionably exploit vulnerabilities.

But the available evidence reviewed for this article does not independently establish that Qilin used CVE-2026-45659 to attack Tommer Construction.

That distinction prevents a common cybersecurity reporting mistake: taking two real events and presenting them as one confirmed chain of events without sufficient evidence.

The broader relationship is still important.

A vulnerability that provides attackers with remote code execution can become an entry point for credential theft, lateral movement, persistence, data theft, and eventually ransomware deployment.

Why One Vulnerability Can Become a Company-Wide Crisis

A vulnerable SharePoint server should never be viewed as merely a single compromised application.

Enterprise applications are connected to identities, databases, file shares, domain services, backup infrastructure, email systems, administrative accounts, and other internal resources.

Once an attacker obtains execution on a server, the next objective may be escalation.

The attacker may attempt to discover credentials.

They may search for service accounts.

They may map internal systems.

They may identify backup servers.

They may look for sensitive documents.

They may attempt to move laterally.

And only after establishing sufficient control might they deploy ransomware.

This is why ransomware defense increasingly begins before encryption.

Data Theft Can Be More Valuable Than Encryption

Modern ransomware operations frequently combine encryption with extortion.

The attacker may steal sensitive information before encrypting systems and later threaten to publish or sell the stolen material.

For a construction company, potentially valuable information could include contracts, employee records, financial information, engineering documentation, customer information, project files, supplier agreements, and internal communications.

That creates a second layer of risk.

Even if backups successfully restore the encrypted systems, stolen data cannot simply be “restored” to safety.

Once information has left the network, the victim may have limited control over what happens next.

Why Backups Alone Are Not Enough

The traditional ransomware defense strategy was simple: maintain backups and restore everything after an attack.

That remains essential, but modern ransomware has made the strategy more complicated.

Attackers increasingly attempt to identify backup systems before encryption.

If backups are connected to the same compromised environment, attackers may attempt to delete or encrypt them.

Organizations therefore need isolated, protected, and regularly tested backups.

A backup that exists but cannot be restored under pressure is not a reliable recovery strategy.

Patch Management Is Now an Incident-Response Function

The SharePoint situation illustrates a larger cybersecurity lesson.

Patching is often treated as routine IT maintenance.

But when a vulnerability enters an active-exploitation catalog, patch management becomes part of incident response.

Security teams should not simply install the update and move on.

They should determine whether the vulnerable system was exposed.

They should investigate authentication logs.

They should review unusual administrative activity.

They should inspect web-server and SharePoint logs.

They should look for unexpected processes and persistence mechanisms.

They should investigate suspicious outbound traffic.

And they should determine whether credentials or cryptographic material may have been exposed.

A Patch Does Not Erase the Past

One of the most dangerous misconceptions in vulnerability management is believing that applying a patch automatically means the incident is over.

A patch closes the vulnerability.

It does not necessarily remove an attacker who exploited it yesterday.

If an adversary already established persistence, stole credentials, created accounts, planted malware, or extracted sensitive information, updating the vulnerable application may only close the original entrance.

The attacker could already be somewhere inside the building.

That is why

GovDelivery

The Importance of Authentication Security

Because CVE-2026-45659 involves authenticated access, identity security becomes particularly important.

Organizations should examine which accounts have access to SharePoint.

They should remove unnecessary privileges.

They should disable stale accounts.

They should enforce strong authentication controls where supported.

They should monitor unusual sign-ins.

And they should pay close attention to accounts belonging to contractors, former employees, service providers, and external partners.

A low-privilege account should not become the stepping stone to complete infrastructure compromise.

Internet Exposure Creates Additional Risk

CISA has specifically advised organizations to avoid exposing SharePoint servers directly to the internet unless necessary.

Where internet exposure is unavoidable, CISA recommends placing SharePoint behind appropriate application-layer security controls, including a Layer 7 reverse proxy or equivalent protections capable of inspecting and filtering requests.

GovDelivery

This is an important principle beyond SharePoint.

Every internet-facing service expands the attack surface.

Every exposed service needs a reason to exist.

Every exposed service needs monitoring.

And every exposed service needs a rapid patching strategy.

Qilin’s Broader Significance

The alleged Tommer Construction incident also fits into the larger evolution of ransomware.

Groups such as Qilin do not need to rely on a single vulnerability.

They can combine phishing, stolen credentials, vulnerable remote-access systems, compromised third parties, exposed applications, and other initial-access techniques.

This flexibility makes ransomware difficult to eliminate through any single defensive measure.

Blocking malicious emails helps.

Patching helps.

MFA helps.

Endpoint detection helps.

Network segmentation helps.

Offline backups help.

But ransomware resilience comes from combining these layers.

The Human Factor Remains Central

Cybersecurity discussions often focus heavily on vulnerabilities and malware.

Yet compromised credentials remain one of the most powerful weapons available to attackers.

A technically secure server can still become dangerous if an attacker obtains the credentials of someone who can access it.

That makes security awareness, password hygiene, phishing resistance, identity monitoring, and privilege management just as important as software patching.

Attackers do not care whether their initial access came from an elegant exploit or a stolen password.

They only care whether it works.

Construction Needs a Stronger Cybersecurity Mindset

The construction industry has historically been viewed primarily through a physical-security lens.

But modern construction companies increasingly operate as technology-dependent organizations.

Heavy equipment may be digitally monitored.

Projects depend on cloud platforms.

Employees use mobile devices.

Accounting systems are connected to networks.

Engineering files are digitally stored.

Communication is increasingly online.

Supplier relationships are electronically managed.

That means the cyberattack surface has expanded alongside the physical business.

Ransomware Can Stop More Than Computers

The phrase “encrypted files” can make ransomware sound like a data problem.

For a construction company, the reality can be much larger.

A project manager may lose access to critical documents.

A finance team may be unable to process payments.

A procurement department may lose supplier information.

A field team may be unable to retrieve project documentation.

Executives may lose visibility into operations.

Employees may lose access to email.

Customers may be unable to communicate with the company.

In severe cases, the digital disruption can begin affecting physical operations.

The Real Cost of Ransomware

The ransom demand is only one component of the economic impact.

There can also be investigation costs.

Incident-response expenses.

Legal costs.

System reconstruction.

Lost productivity.

Delayed projects.

Customer compensation.

Regulatory obligations.

Cyberinsurance complications.

Reputational damage.

And potentially long-term loss of trust.

This is why focusing exclusively on the ransom amount misses the bigger picture.

The true cost of ransomware is the disruption of business continuity.

Deep Analysis: What Defenders Should Do Now

Command 01 — Identify Every SharePoint Server

Security teams should immediately identify every on-premises SharePoint Server instance operating within the organization.

Unknown servers create unknown risk.

Command 02 — Confirm Patch Levels

Administrators should compare installed builds against

Systems below the affected thresholds should be treated as urgent remediation candidates.

National Vulnerability Database

Command 03 — Determine Internet Exposure

Organizations should identify which SharePoint servers can be reached from the public internet.

Internet-facing systems deserve immediate priority because they provide attackers with a potentially direct attack surface.

Command 04 — Review Authentication Logs

Security teams should examine authentication activity for suspicious accounts, unusual locations, abnormal times, unexpected access patterns, and unusual privilege use.

Command 05 — Investigate Existing Compromise

If a server remained vulnerable during the period of active exploitation, administrators should not assume that no compromise occurred simply because no obvious disruption was observed.

Command 06 — Search for Persistence

Investigators should examine systems for unexpected accounts, scheduled tasks, services, web shells, unusual processes, and other indicators of persistence.

Command 07 — Protect Credentials

Potentially exposed credentials should be reviewed and, where appropriate, rotated.

Privileged credentials deserve special attention because compromise of an administrative identity can dramatically increase the blast radius.

Command 08 — Inspect Network Movement

Defenders should investigate unusual traffic from SharePoint servers toward internal systems.

A server that suddenly communicates with systems it historically never contacted deserves investigation.

Command 09 — Verify Backups

Organizations should confirm that backups are available, isolated, intact, and capable of being restored.

A backup strategy should be tested rather than assumed.

Command 10 — Segment Critical Systems

Network segmentation can prevent a compromised application server from becoming a bridge into the entire organization.

Command 11 — Monitor for Ransomware Indicators

Security teams should watch for abnormal file modifications, mass encryption behavior, suspicious administrative tools, credential dumping, lateral movement, and unexpected data transfers.

Command 12 — Treat Unconfirmed Claims Seriously but Carefully

A ransomware claim should not automatically be accepted as fact.

But it should not automatically be ignored either.

Threat intelligence teams should treat credible claims as potential indicators requiring validation.

Command 13 — Establish a Crisis Playbook

Organizations should know in advance who makes decisions during a ransomware incident.

Waiting until systems are encrypted to determine who leads the response can cost valuable time.

Command 14 — Protect Recovery Infrastructure

Backup systems should have stronger protections than ordinary endpoints.

If attackers can compromise the recovery environment, the organization’s last line of defense can disappear.

Command 15 — Assume Attackers May Move Quietly

The absence of encryption does not mean the absence of compromise.

Modern intrusions can remain hidden while attackers collect credentials, map networks, and steal information.

Command 16 — Make Vulnerability Intelligence Actionable

Security teams should prioritize vulnerabilities based not only on severity scores but also on evidence of exploitation.

CVE-2026-45659 is a strong example of why.

Command 17 — Reduce Attack Surface

Unused services should be removed.

Unnecessary internet exposure should be eliminated.

Old accounts should be disabled.

Excessive permissions should be reduced.

Command 18 — Prepare for Double Extortion

Organizations should assume that ransomware incidents may involve both encryption and data theft.

Recovery planning should therefore include breach-response procedures.

Command 19 — Coordinate IT and Security

Patch management cannot remain isolated inside the IT department.

Security teams need visibility into patch status, while IT teams need threat intelligence about actively exploited vulnerabilities.

Command 20 — Verify Before Publishing

Cybersecurity reporting should distinguish between confirmed incidents, credible claims, and speculation.

That standard protects both readers and victims from misinformation.

What Undercode Say:

The First Lesson Is Verification

The Tommer Construction claim is concerning, but the available evidence does not currently provide enough independent confirmation to state that Qilin definitely compromised the company.

The Second Lesson Is Urgency

The SharePoint vulnerability is different. CISA and NIST provide authoritative evidence that CVE-2026-45659 exists and that it has been actively exploited.

National Vulnerability Database

+1

Ransomware Does Not Need a Zero-Day

Attackers frequently gain enormous leverage from vulnerabilities that defenders already know about but have failed to remediate.

Exposure Is the Multiplier

An unpatched server is dangerous.

An unpatched server exposed to the internet is considerably more dangerous.

Credentials Matter

Authenticated exploitation demonstrates why identity security must be treated as part of vulnerability management.

The Initial Access Problem Is Growing

Ransomware groups can combine vulnerabilities, stolen credentials, phishing, and compromised infrastructure to reach the same objective.

Construction Is Not Immune

Construction businesses increasingly rely on digital systems and therefore face the same cyber risks as other modern enterprises.

Operational Technology Is Not the Only Concern

Even when physical machinery remains operational, the systems managing projects, finance, logistics, and communications can be disrupted.

Backups Remain Essential

A resilient backup strategy can transform ransomware from a potentially catastrophic event into a major but recoverable incident.

Backups Must Be Isolated

If attackers can reach the backup environment with compromised credentials, recovery becomes much more difficult.

Patching Is Only Step One

Organizations need to determine whether exploitation happened before the patch was installed.

Detection Must Continue After Remediation

Security monitoring should continue even after vulnerable software has been updated.

Ransomware Is an Ecosystem

Qilin and other ransomware operations benefit from a broader criminal market involving initial access, stolen credentials, malware development, extortion, and data brokerage.

Extortion Changes the Equation

Encryption is no longer necessarily the final objective.

Data theft can provide attackers with a second pressure mechanism.

The Cost Extends Beyond the Ransom

Business interruption can become more expensive than the original ransom demand.

Security Teams Need Context

A CVSS score alone cannot explain the real-world danger of a vulnerability.

Active Exploitation Changes Everything

Once exploitation is confirmed, organizations should accelerate remediation regardless of whether the vulnerability was previously considered a lower operational priority.

Internet-Facing Systems Deserve Priority

Attack surface reduction should begin with systems accessible from outside the organization.

Authentication Needs Continuous Monitoring

A legitimate login can still be malicious when an attacker controls the credentials.

Least Privilege Matters

Reducing unnecessary permissions limits what attackers can do after gaining access.

Segmentation Limits Damage

Network segmentation can prevent one compromised server from becoming a gateway to the entire enterprise.

Ransomware Defense Begins Before Encryption

Once encryption starts, defenders may already be several steps behind.

Threat Hunting Is Increasingly Important

Organizations should search proactively for signs of compromise instead of waiting for an obvious ransomware event.

Vulnerability Management Needs Intelligence

The most dangerous vulnerability is not necessarily the one with the highest numerical score.

It is often the one attackers are exploiting right now.

The SharePoint Case Is a Warning

CVE-2026-45659 demonstrates how quickly a software flaw can move from disclosure to active exploitation.

CISA’s KEV Catalog Matters

Security teams should incorporate

Ransomware Claims Require Editorial Discipline

Publishing an allegation as a confirmed breach can create unnecessary panic and damage credibility.

But Claims Should Not Be Ignored

An unverified ransomware claim can still provide an early signal for organizations to investigate.

Transparency Is Better Than Certainty Without Evidence

Using words such as “allegedly” and “claimed” is not weakness.

It is responsible cybersecurity reporting.

The Biggest Risk Is Complacency

Organizations often know which systems are vulnerable.

The danger comes when remediation is postponed because exploitation has not yet been observed.

Attackers Do Not Wait for Perfect Conditions

They scan continuously and exploit opportunities whenever they find them.

Small Companies Can Carry Valuable Data

A company does not need to be a multinational corporation to become a profitable ransomware target.

Digital Dependency Creates Concentration Risk

When many business functions depend on the same digital infrastructure, one incident can disrupt multiple departments simultaneously.

Recovery Should Be Practiced

An organization should know how it will operate when email, file servers, identity systems, and business applications suddenly disappear.

Cybersecurity Is Business Continuity

Ransomware is not merely an IT problem.

It is a threat to the

The Final Warning

Whether or not the Tommer Construction claim is ultimately confirmed, the SharePoint exploitation evidence provides a much broader warning: attackers are actively looking for vulnerable enterprise systems, and organizations that delay remediation may eventually pay a much higher price.

✅ CVE-2026-45659 Is Real

NIST confirms CVE-2026-45659 as a Microsoft SharePoint vulnerability with a CVSS 3.1 score of 8.8, and CISA lists it in its Known Exploited Vulnerabilities catalog.

National Vulnerability Database

✅ SharePoint Exploitation Has Been Confirmed

CISA has explicitly warned that threat actors are actively exploiting CVE-2026-45659 and other SharePoint vulnerabilities against on-premises SharePoint servers.

GovDelivery

❌ The Tommer Construction Qilin Attack Is Not Independently Confirmed

The supplied claim says Qilin encrypted Tommer

Prediction

(+1) Active Exploitation Will Keep Driving Emergency Patching

Organizations running vulnerable on-premises SharePoint servers are likely to accelerate remediation as security teams recognize that CVE-2026-45659 is not merely a theoretical weakness but an actively exploited vulnerability.

(+1) Ransomware Operators Will Continue Targeting Unpatched Enterprise Systems

Criminal groups have strong financial incentives to exploit vulnerabilities that provide reliable access to business environments.

(+1) Identity Security Will Become Even More Important

As attackers increasingly combine stolen credentials with software vulnerabilities, organizations will place greater emphasis on authentication monitoring, least privilege, and privileged-account protection.

(+1) Ransomware Defense Will Shift Further Toward Detection

Organizations will increasingly focus on identifying attackers during reconnaissance, credential theft, lateral movement, and data exfiltration rather than waiting until files are encrypted.

(-1) Unverified Ransomware Claims Will Continue Creating Confusion

Threat-monitoring feeds and social-media accounts will likely continue publishing alleged victim lists before organizations publicly confirm incidents, making independent verification increasingly important.

(+1) SharePoint Will Remain a High-Value Target

As long as organizations continue operating internet-accessible on-premises SharePoint infrastructure, vulnerabilities capable of enabling remote code execution will remain attractive to attackers.

(+1) The Biggest Advantage Will Belong to Prepared Organizations

Companies that combine rapid patching, strong identity security, network segmentation, threat hunting, and isolated backups will have a significantly better chance of containing ransomware before it becomes a business-wide crisis.

▶️ Related Video (80% Match):

🕵️‍📝Let’s dive deep and fact‑check.

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

References:

Reported By: x.com
Extra Source Hub (Possible Sources for article):
https://www.pinterest.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube