Construction has become the single most targeted industry for spearphishing, according to threat research firm ReliaQuest, for two years running. In September 2025 alone, construction and engineering accounted for 11.4% of all publicly reported ransomware and business email compromise attacks — more than any other sector tracked that month.
Every trade on a job site shares some version of that exposure. General contractors carry a different version of it. A single electrician or plumber has to protect one business’s worth of payment relationships. A GC manages a draw schedule running through dozens of subs at once, each with its own bank details, its own invoices, and its own place in a payment chain that the GC is the one actually disbursing.
Why the GC Position Is Structurally Different
Here’s roughly how it plays out, based on the pattern seen across construction BEC cases: an email arrives that looks completely ordinary — a subcontractor’s routine note about updated banking details for the next draw. The address looks right. The signature matches. The message references the actual project by name, because the attacker has been quietly reading the real thread. The payment goes out. Days or weeks later, the actual subcontractor calls asking where their money is. By then the funds are gone, un-reversible, sitting in an account nobody can trace — and the GC still owes that subcontractor the money a second time, out of pocket.
That scenario is available to any construction business with an inbox. What makes it worse for a GC specifically is scale: a compromised account or a single successful impersonation doesn’t threaten one payment, it threatens every draw disbursement in flight on every active project at once.
The Pressure Is Coming From Both Directions
Two things are happening at the same time, and both point at the GC. Project owners and lenders are increasingly adding cyber coverage requirements to subcontractor and contractor insurance requirements — losing a bid over the absence of cyber coverage is a real, current scenario, not a hypothetical one. Surety underwriters are moving the same direction: bonding companies are starting to factor cybersecurity posture into risk assessment, for a straightforward reason — a ransomware attack that shuts down a bonded contractor mid-project is a completion risk, and completion risk is exactly what a bond exists to cover.
At the same time, GCs are the ones increasingly asking subs to prove their own security posture before award — the flip side of the same dynamic. A general contractor today is being vetted from above by owners, lenders, and sureties, while doing the vetting themselves on everyone working beneath them. There’s no position on a job site that sits at that particular intersection except the GC.
What’s Actually at Stake Beyond the Wire Transfer
Payment fraud gets most of the attention because the number is easy to point to, but it’s not the only exposure. Verizon’s 2026 Data Breach Investigations Report found ransomware present in 48% of breaches industry-wide. On a construction project specifically, a locked project management or scheduling system doesn’t just cost the GC a day — it stalls every trade sequenced behind it, on a schedule that usually has real financial penalties attached to slipping.
What Actually Helps
None of this means treating every subcontractor email as suspect. It means having a verification habit for anything touching banking details — a phone call to a known number, not a reply to the email that requested the change — email protection that catches the impersonation attempt before it reaches whoever approves draws, and monitoring for the kind of account compromise that lets an attacker sit quietly in a real thread long enough to make the impersonation convincing.
For the fuller picture on why trades and contractors are being targeted more deliberately, and what’s actually included in a plan built around this kind of business, see the full Cybersecurity for Contractors & Trades page.