Ransomware victim disclosure
← All victimsMomentum Telecom
Claimed by EndZone · listed 4 hours ago
Status timeline
- ListedSep 22, 2026
Current state: Listed for ransom
At a glance
- Group
- EndZone
- Status
- Listed for ransom
- Country
- United States
- Sector
- Telecommunications
- Listed on leak site
- Sep 22, 2026
- Records
- 7500000
About the victim
AI dossier — public-source company profileMomentum Telecom is a telecommunications company founded in 2001 that provides cloud-based communication solutions for businesses, specializing in cloud voice services, managed networks, SD-WAN solutions, and Microsoft Teams Phone integration. The company offers global internet connectivity, collaboration tools, and network security services.
- Industry
- Telecommunications & Cloud Communications
- Founded
- 2001
Attack summary
Severity: critical — Confirmed exfiltration of PII at massive scale (7.5 million users) plus operational disruption (58,127 users cut from service). Affects critical telecommunications infrastructure impacting families, businesses, and students.EndZone claims to have accessed a diagnostic and provisioning tool through a compromised Multi-Service Operator (MSO), exfiltrating personally identifiable information for over 7.5 million users across multiple MSOs. The group also claims to have deleted modem packages for 58,127 users, disrupting internet and voice services.
Data the group says was taken
AI dossier — extracted from the leak post- PII for 7.5 million users
- User names and email addresses
- Phone numbers
- Billing account information
- Customer service records
- Salesforce customer data
- Device and service upgrade records
What the group claims
Momentum is a telecommunications company founded in 2001 providing cloud-based communication solutions for businesses, specializing in cloud voice services, managed networks, SD-WAN solutions, and Microsoft Teams Phone integration. Attackers gained access to a diagnostic and provisioning tool used by Momentum through a compromised Multi-Service Operator (MSO). The tool controls internet and voice services for millions of users across global markets. PII for over 7.5 million users was exposed across every MSO. Modems were removed for 58,127 users across the United States, cutting off internet service.
The leak post
captured from the group's siteData will be public on: September 24, 2026 Initial access was via a CX contractor doing business with AT&T. Access originally used as vehicle for Equipment Changes/Call Forwarding (thanks a lot TORCH patch) - VPN + HVD (both external and internal MyDesktop) instances were accessed for a prolonged period without any detection or incident response taking place. Certificates exported from certlm in the VDI + OPUS self installer (automatically joins EP to S1) opened up the door to the VPN. Salesforce data was accessed via a project manager ATTUID + a DirecTV contractor who for some reason had the apps available in Salesforce. AT&T CSO, if you are reading this, you are to contact us ASAP! Data will be public on: October 20, 2026 Momentum is a telecommunications company founded in 2001 that provides cloud-based communication solutions for businesses, specializing in cloud voice services, managed networks, SD-WAN solutions, and Microsoft Teams Phone integration. We gained access to a diagnostic and provisioning tool used by Momentum through a compromised Multi-Service Operator (MSO). Upon reconnaissance, we identified multiple critical vulnerabilities throughout the system. This tool con…
Data the group says was taken
- PII
- customer records
- user data
- email addresses
- phone numbers
Screenshot of the leak post

Sources
Source
Indexed 4 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

