Ransomware victim disclosure
← All victimsAT&T
Claimed by EndZone · listed 5 hours ago
Status timeline
- ListedSep 18, 2026
- Data leakeddate unknown
At a glance
- Group
- EndZone
- Status
- Data leaked
- Country
- United States
- Sector
- Technology
- Listed on leak site
- Sep 18, 2026
About the victim
AI dossier — public-source company profileAT&T is a major U.S. telecommunications company with annual revenue of $125.6 billion, providing wireless, wireline, and digital entertainment services including DirecTV.
- Industry
- Telecommunications
Attack summary
Severity: high — Confirmed exfiltration of internal infrastructure credentials and access to enterprise systems (VDI, VPN, Salesforce). Prolonged undetected access to critical telecommunications infrastructure represents significant operational and data security risk, though no specific regulated/PII datasets are explicitly named.EndZone claims initial access via a contractor vulnerability (CX/TORCH patch), followed by prolonged unauthorized access to external and internal VPN and virtual desktop instances. The group accessed certificates from VDI environments and Salesforce data via compromised contractor and project manager accounts, exploiting inadequate detection and incident response.
Data the group says was taken
AI dossier — extracted from the leak post- VDI certificates
- VPN access credentials
- Salesforce project data
- Internal MyDesktop instances
What the group claims
Revenue: $125.6 billion Initial access was via a CX contractor doing business with AT&T. Access originally used as vehicle for Equipment Changes/Call Forwarding (thanks a lot TORCH patch) - VPN + HVD (both external and internal MyDesktop) instances were accessed for a prolonged period without any detection or incident response taking place. Certificates exported from certlm in the VDI + OPUS self installer (automatically joins EP to S1) opened up the door to the VPN. Salesforce data was accessed via a project manager ATTUID + a DirecTV contractor who for some reason had the apps available in Salesforce. AT&T CSO, if you are reading this, you are to contact us ASAP!
Sources
- Victim siteatt.com
Source
Indexed 5 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

