Bid tools, client portals, and subcontractor management apps built with AI now hold six- and seven-figure payment schedules, homeowner PII, and subcontractor SSNs - exactly what construction's #1 threat, business email compromise, is built to exploit. The FBI counted .046 billion in BEC losses in 2025, and AI-generated code introduces vulnerabilities in roughly 45% of tasks (Veracode).
Get a Free Security Scan See Our AI App AuditConstruction ranks in the top three ransomware-targeted industries and is the most-targeted vertical for vendor email compromise - a combination of high cash flow and low IT maturity that AI-built apps don't fix on their own.
Bid sheets, unit pricing, and margin data in an unsecured database leak competitive intelligence to anyone who queries the API. Lovable's CVE-2025-48757 row-level-security misconfig let strangers query exactly this kind of table, and a Lovable-hosted app was found leaking 18,697 users' data via 16 vulnerabilities in February 2026.
A portal that displays a project's draw schedule tells an attacker precisely when and how much to ask for in a spoofed wire request. A lookalike-domain scam diverted a .9 million payment intended for Rodgers Builders from Appalachian State University, and a Washington County, PA demolition contractor's own compromised email led to a misdirected payment on a courthouse job.
Sub-onboarding apps hold W-9s, SSNs, certificates of insurance, and certified payroll data - all notification-triggering under all 50 states' breach laws. Akira ransomware's February 2026 claim against Williams Brothers Construction listed "personal files of employees" among 90GB allegedly stolen.
Stored banking details and invoice history are raw material for funds-transfer fraud - the average Coalition-tracked funds-transfer-fraud claim in 2025 was and 86% of fraudulent BEC payments move by wire or ACH, which rarely comes back once sent.
Text-back and quote-request forms built with AI routinely skip documented TCPA consent, exposing contractors to β per text with no cap. A class action against Angi over contractor-lead texts was filed in October 2025 - the same exposure applies to any AI-built lead form.
Geotagged photos of homeowner properties, gate codes, and access notes are physical-security data, not just business records. AI-generated Supabase backends shipped without row-level security have already exposed this kind of data - the same Lovable-hosted app noted above leaked 18,697 users' records.
| Regulation | When it triggers | Penalty |
|---|---|---|
| Wire fraud / BEC (FBI IC3) | Any emailed payment instructions on draws/invoices; compromised email makes the firm the fraud vector | Avg loss K/BEC; .046B total reported in 2025 |
| State breach-notification (all 50) | Exposure of SSN/DL/financial account of employees, subs, or homeowners | Mandatory notification + state AG enforcement |
| CCPA/CPRA | For-profit CA business over thresholds; homeowner/lead PII in portals and lead forms | Up to intentional per consumer (2025 figures) |
| TCPA | Texting leads without prior express written consent | β per call/text, uncapped |
| PCI DSS | Card payments/deposits through a self-built checkout | βnth; loss of processing |
| CMMC 2.0 | Contractors/subs on DoD projects handling FCI/CUI; clauses phasing in from 2025-11-10 | Ineligibility for DoD contracts; False Claims Act exposure for false attestations |
| State contractor licensing (e.g. CA CSLB) | Consumer complaints from fraud or mishandled funds on home-improvement jobs | Citations up to standard / serious; license discipline |
Not by default. AI-generated code introduces vulnerabilities in roughly 45% of tasks (Veracode), and a Lovable-hosted construction app was found leaking 18,697 users' data via 16 vulnerabilities in February 2026. Before handling draw payments or invoices, confirm row-level security is enabled and payment instructions require call-back verification.
Require phone call-back verification using a known number - not one in the email - before acting on any change to wire instructions. 86% of fraudulent BEC payments move by wire or ACH and rarely come back, and the average funds-transfer-fraud claim in 2025 was .
A lookalike-domain scam diverted a .9 million payment intended for contractor Rodgers Builders from Appalachian State University. Separately, Washington County, PA wired to a scammer after a demolition contractor's own email was compromised on a courthouse demolition project.
Yes, if you or your subs work on DoD projects handling Federal Contract Information or Controlled Unclassified Information. CMMC 2.0 clauses began phasing into contracts on November 10, 2025, and non-compliance can mean ineligibility for DoD work plus False Claims Act exposure for false attestations.
Yes. Texting leads without prior express written consent carries β in per-text penalties with no cap. A TCPA class action was filed against Angi in October 2025 over exactly this kind of contractor-lead texting.
Rotate every API key and credential, enable row-level security if it wasn't already on, and notify affected employees, subcontractors, and clients under applicable state breach laws - construction breaches routinely expose SSNs, financials, and project/client files together.
We audit AI-built contractor portals, bid tools, and sub-management apps for wire-fraud exposure, missing RLS, and exposed data - then fix what we find.
Get a Free Security Scan