Ransomware victim disclosure
← All victimsMomentum
listed as Gomomentum.com · Claimed by EndZone · listed 3 hours ago
Status timeline
- ListedSep 21, 2026
- Data leakeddate unknown
At a glance
- Group
- EndZone
- Status
- Data leaked
- Listed on leak site
- Sep 21, 2026
About the victim
AI dossier — public-source company profileMomentum is a telecommunications company founded in 2001 that provides cloud-based communication solutions for businesses, including cloud voice services, managed networks, SD-WAN solutions, and Microsoft Teams Phone integration. The company operates globally with offices in New York, Toronto, London, Berlin, Tokyo, Beijing, Sydney, and Dubai, and generates approximately $221.7 million in annual revenue.
- Industry
- Telecommunications & Cloud Communications
- Founded
- 2001
Attack summary
Severity: critical — Confirmed exfiltration of PII at massive scale (7.5+ million users) combined with operational disruption (58,127 users without internet service). The attack impacts critical infrastructure—a telecommunications provider serving millions—and demonstrates both data theft and active service disruption capability.EndZone claims to have compromised a diagnostic and provisioning tool used by Momentum through a Multi-Service Operator (MSO), gaining access to personally identifiable information (PII) for over 7.5 million users. The group also claims to have disrupted service by removing modem packages for 58,127 users across the United States and states they possess the ability to restore these services upon contact.
Data the group says was taken
AI dossier — extracted from the leak post- PII for 7.5+ million users
- Customer data across all MSOs
- Modem provisioning records
What the group claims
Revenue: $221.7 million Momentum is a telecommunications company founded in 2001 that provides cloud-based communication solutions for businesses, specializing in cloud voice services, managed networks, SD-WAN solutions, and Microsoft Teams Phone integration. We gained access to a diagnostic and provisioning tool used by Momentum through a compromised Multi-Service Operator (MSO). Upon reconnaissance, we identified multiple critical vulnerabilities throughout the system. This tool controls internet and voice services for millions of users across global markets. We successfully accessed user data for every MSO, exposing personally identifiable information (PII) for over 7.5 million users. They didn't notice the prolonged access or the customer data dump for a while, but when we started deleting modems they noticed. They kept burning access and we gained it back, they'd burn it again. We removed modem packages for 58,127 users across the United States. That's 58,127 people without internet service right now. Families, businesses, students all cut off from the digital world. This is the direct result of their negligence and failure to secure their systems. These services can be restored immediately with the click of a button on our tool but you must reach out. Momentum management should contact us to discuss resolution.
Sources
- Victim siteGomomentum.com
Source
Indexed 3 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

