August 17, 2026
Ransomware Gangs Are Coming for HVAC and Plumbing Shops
Two HVAC companies were named on ransomware leak sites in one week. What mechanical and plumbing contractors should take from it, from a Florida MSP.
Chris Archer Sales & Marketing Director
Reviewed by Reade Taylor, Founder & President Two HVAC companies, one bad week
On August 3, the Akira ransomware crew added Albers Mechanical Contractors, a US mechanical contractor with more than 50 years in business, to its extortion leak site. The listing, tracked by ransomware.live and reported by DeXpose, claims the group stole 30GB of data. In the attackers’ own words: employee information, financials, contracts and agreements, NDAs, and customer information.
The same day, a second crew called SafePay listed Multiaqua, an American manufacturer of air-cooled chillers and hydronic HVAC equipment, with the usual threat attached. Pay up or the files get published.
Worth being clear about what these listings are. They’re claims made by criminals on their own sites, tracked by monitoring services, and neither company has publicly confirmed the details as of this writing. But the pattern matters more than any single listing. Two HVAC industry names on extortion sites in the same week is not a coincidence. It’s a segment getting worked.
The numbers behind the pattern
Dragos published its Q2 2026 industrial ransomware analysis on August 10, and it puts hard numbers on what trade contractors have been feeling. The firm tracked 1,140 ransomware incidents against industrial organizations in the quarter, up 12 percent from 1,020 in Q1. North America took 514 of them. Akira, the group that listed Albers, grew from 100 claimed victims in Q1 to 129 in Q2.
Two findings in that report should land hard for anyone running a mechanical, HVAC, or plumbing shop.
First, construction logged 176 incidents in a single quarter, and companies that support industrial environments, meaning engineering firms, system integrators, and equipment manufacturers, logged another 117. Attackers are deliberately going after the contractors and vendors around big facilities, not just the facilities themselves.
Second, the report found that social engineering was the most consistently reported way in. That includes attackers impersonating IT support over Microsoft Teams and phone calls, and abusing legitimate remote-access tools like AnyDesk, QuickAssist, and SimpleHelp. Nobody hacked a chiller. They called the office pretending to be the help desk, and someone believed them.
Stuck on something like this right now?
Talk it through with a real US-based engineer, 24/7, no phone trees: (407) 587-0089.
Book a Free Strategy SessionWhy a 40-person shop is a target
Trade contractors tend to assume they’re too small to interest anyone. The history says otherwise. The 2013 Target breach, one of the largest retail card breaches on record, started with network credentials stolen from an HVAC contractor that serviced Target stores. Attackers have understood for over a decade that the mechanical contractor is often the softest way into a bigger prize.
And even setting client access aside, look at what Akira claims it took from Albers. Employee records, financials, contracts, customer data. Every shop running QuickBooks, a shared drive, and a field-service app holds exactly that. If it gets published, you’re writing notification letters to employees and customers, answering questions from GCs during prequalification, and explaining the incident to your insurance carrier for years.
There’s also a quieter cost. Your dispatch board, your scheduling, your invoicing, your service history. If those get encrypted on a Tuesday, trucks don’t roll Wednesday. Dragos made this exact point: attackers don’t need to touch control systems or any equipment in the field, because taking down ordinary office IT is enough to stop the business cold.
What’s actually worth doing
None of this requires an enterprise budget. It requires a handful of controls done consistently, which is where most shops fall down.
Turn on multi-factor authentication everywhere it’s offered, starting with email, VPN, and anything financial. Akira’s known playbook leans on VPN access without MFA.
Get backups that live somewhere ransomware can’t reach, and test a restore. A backup you’ve never restored from is a hope, not a plan.
Lock down remote-access tools. If AnyDesk or QuickAssist isn’t something your business deliberately uses, it shouldn’t run on your machines at all. If you remote into customer building systems, that access deserves the same care as your bank login.
Give your people a way to verify who’s calling. The fake IT support call works because nobody at the shop knows who real IT support is or how they reach out. It’s exactly why Cyber Command uses double-blind user verification. When someone calls our help desk claiming to be one of your employees, or someone contacts your team claiming to be us, both sides confirm identity through a separate channel agreed on in advance, before any password reset or remote session happens. Neither side takes an inbound call at face value. The whole approach is designed to turn the impersonation play into a dead end.
A managed security setup built around monitoring, MFA, and tested recovery is designed to cut off the most common paths in and shorten the bad day if one gets through. No honest provider will promise you’ll never be hit. The goal is to be a harder target than the next contractor on the list, and to be back up in hours instead of weeks.
If you already pay someone for IT
Plenty of contractors reading this have an IT guy, or a small provider they’ve used since 2015. Fair enough. The useful question isn’t whether you pay for IT, it’s whether the basics above are actually in place. Ask for evidence. When was the last restore test? Is MFA on every mailbox, or just some? Who watches for a login from a strange country at 2 a.m.?
If the answers are vague, or the response time on ordinary tickets already frustrates you, that’s worth acting on before an incident forces the issue. We wrote up how a clean handover works, including what to do when the old provider drags their feet, on our switching IT providers page. Moving doesn’t have to be painful, and it costs nothing to compare.
Built for the trades
Cyber Command builds IT support for HVAC and plumbing companies across Orlando, Tampa Bay, and Jacksonville, part of our broader industrial services practice, with 24/7 help from real humans. No phone trees, no ticket black holes. We know what a dispatch board going down at 7 a.m. costs you, and we build around keeping crews moving. You can see how we handle other industries too.
If the Albers listing made you wonder what an attacker would find in your shop, that’s a reasonable thing to wonder. Call (407) 587-0089 or reach out here and we’ll walk through it with you, plainly and without a sales script.
This article is for general informational purposes only and is not legal, compliance, insurance, or other professional advice. Threats, technologies, and regulations change quickly; confirm current requirements with your own advisors before acting. See our full disclaimer.