Back to Exposure Report
Construction SoftwareAugust 26, 2026United States / Global

Procore Technologies

Construction software holds the plans for buildings that are still standing, still occupied, and still using the access control layout in the file.

Not yet disclosedDrawings and structural plans (inferred)Site access and security layouts (inferred)Subcontractor workforce records (inferred)
1

What happened?

Procore Technologies was listed by an actor operating as OROVA on August 26, 2026. The listing has not been independently verified, the company has not publicly confirmed an incident, and no data types have been disclosed as of this writing.

Procore builds construction management software used across commercial, industrial, institutional, and public sector projects.

2

What data was actually inside?

Not disclosed. What a construction management platform holds, labeled as inference from the product's function: architectural drawings and structural plans, mechanical and electrical layouts, site access procedures, security system installation details, inspection and compliance records, contracts, and daily site logs.

There is also a workforce layer. Construction platforms carry subcontractor records, worker certifications, and safety incident reports for the many small trade businesses working on each project.

3

Who gets hurt and how?

For an ordinary office development, exposed plans are commercially sensitive and little more. The harm profile changes entirely with the building type.

Plans for a data centre, a hospital, a courthouse, a utility substation, or a school describe the location of the electrical room, the routing of network infrastructure, the placement of access control readers and cameras, and the points at which the building can be entered. Those buildings exist now and people are inside them. Documentation of that kind is operational security information about a physical target, and unlike a password it cannot be changed after disclosure.

The workforce layer carries a more ordinary harm to people who have the least protection: subcontractor employees whose certifications, injuries, and personal details sit in a platform their employer never assessed and they never heard of.

4

What did they think they were doing right?

While not publicly confirmed for Procore, enterprise construction platforms serving public sector and institutional clients typically hold recognised security certifications, because government and institutional procurement requires them.

Certification frameworks assess controls against a defined scope, and the scope is almost always framed around personal data and service availability. A building's electrical layout is neither. It passes through the assessment as project content — the customer's material, held on the customer's behalf — without ever being classified by what disclosure of it would enable.

5

What did they not know about their own data?

Data classification asks a consistent question: does this record identify a person, and does it contain a regulated element. That question is well designed for privacy risk and blind to physical risk.

A floor plan identifies nobody. It contains no regulated element. It would be rated low sensitivity by every classification tool in common use, while describing exactly how to enter a building unobserved. The same blind spot covers facility diagrams, network topology documents, guard rotation schedules, and the site plans held by architecture and engineering firms.

For a platform holding project data across thousands of buildings, the question of which of those buildings are sensitive is not answerable from the schema. It requires knowing what the projects are.

If you use cloud storage, do you know what sensitive data lives in your buckets and blobs? Or would you find out the same way they did?

6

What does attribution look like the morning after?

Personal data notification obligations would attach to the workforce records — names, certifications, and safety incident details for subcontractor employees engage state statutes and, for international projects, GDPR.

The plans themselves generate almost no statutory obligation and a great deal of contractual and practical work. Every affected project owner needs to know whether their building's documentation was included, and for government, healthcare, and critical infrastructure clients that conversation may trigger physical security reviews and, in some cases, changes to the buildings themselves. There is no regulator to file with and no template for the notification.

7

What would have changed the outcome?

A classification model that asks whether a record identifies a target, not only whether it identifies a person.

Privacy regulation trained a generation of data governance to look for personal identifiers, and it does that well. Facility plans, network diagrams, security schedules, and site documentation pass through every one of those checks unflagged while being directly useful to someone planning a physical intrusion. If your organisation holds documentation of buildings, infrastructure, or physical security arrangements, none of it is on your data map — because nothing ever required it to be. See also our analysis of the Cl0p PTC Windchill campaign, where facility images and project plans were among the claimed losses.

Procore Technologies found out the hard way.

Your team could spend the next 6 months rebuilding systems, notifying customers, and answering legal questions. Or you could spend 24 hours finding out what's actually at risk.