Skip to main content

Ransomware victim disclosure

← All victims

Momentum Telecom

listed as WARNING · Claimed by EndZone · listed 13 hours ago

Today
Age
since listed · data leaked

Status timeline

  1. ListedOct 5, 2026
  2. Data leakeddate unknown

At a glance

Group
EndZone
Status
Data leaked
Listed on leak site
Oct 5, 2026

About the victim

AI dossier — public-source company profile

Momentum Telecom is a telecommunications provider serving approximately 7.5 million customers, with operations including internet service delivery in Utah and surrounding regions.

Industry
Telecommunications
Address
Eagle Mountain, Utah

Attack summary

Severity: critical — Confirmed exfiltration of PII at massive scale (7.5 million customers), combined with demonstrated operational disruption to critical telecommunications infrastructure affecting families, businesses, and students. Publicly corroborated by news coverage of the Eagle Mountain outage.

EndZone claims to have exfiltrated PII of 7.5 million customers and caused widespread operational disruption, including the Eagle Mountain internet outage that received national news coverage. The group states they deleted modems, caused service disruptions lasting days, and repeatedly regained access despite Momentum's security efforts.

critical

Data the group says was taken

AI dossier — extracted from the leak post
  • Personally identifiable information (PII) of 7.5 million customers
  • Network infrastructure data
  • Customer service records

What the group claims

This is what happens when you ignore us or go ghost. Momentum Telecom is a prime example of negligence in action. They don't care about their 7.5 million customers whose PII has been exposed. They don't care about the 100,000+ people who lost internet service due to widespread outages we caused as a direct result of their poor security practices.The Eagle Mountain, Utah "cyberattack" and internet outage that made national news? That was us. That was a direct consequence of Momentum's failure to secure their systems. They ignored repeated warnings, they burned access repeatedly, and we kept gaining it back. We deleted modems, caused service disruptions, and left families, businesses, and students without internet for days. Read the coverage:ABC4|Fox 13Momentum management repeatedly contacted us, then ghosted us every single time. They reached out to initiate negotiations, then disappeared. They agreed to terms, then stopped responding. This pattern continued over and over. They don't take this seriously. They don't care about their customers. Now their data is public and their customers are paying the price for their arrogance.Don't be like Momentum. Don't ignore us. Don't go ghost. When we reach out, we expect a response. When we say we have your data, we have your data. When we say we can cause damage, we can cause damage.Contact us. Negotiate. Resolve this before you become the next headline.

Source

Indexed 13 hours ago

This page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.

Is this your supplier? Your competitor? You?

Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

Disclosure context

About EndZone

EndZone is a ransomware group first observed in September 2026, operating with an apparent financial motivation based on its targeting profile, though limited public documentation exists given its early stage of activity. The group has claimed two known victims to date, with targeting concentrated in the United States across the Government and Defense and Technology sectors, suggesting a deliberate focus on high-value organizations likely to possess sensitive data and the financial resources or political pressure to meet ransom demands. Due to the group's nascent operational history and limited victim count, no detailed technical attribution, affiliation, or country of origin has been publicly established by CISA, the FBI, Mandiant, or other reputable security research organizations at this time. Similarly, specific details regarding initial access vectors, tooling, encryption methodology, or extortion tactics have not yet been publicly documented, though the targeting of government and defense entities is consistent with broader ransomware trends involving double extortion and data exfiltration pressure. No notable high-profile campaigns, law enforcement actions, or confirmed ransom figures have been publicly attributed to EndZone as of the time of this profile, and the group should be considered an emerging threat actor under continued monitoring given its sector targeting patterns. The group has been linked to 9 public disclosures across our corpus. First observed on a leak site on September 18, 2026; most recent post October 5, 2026. The operation is currently active.

Timeline of this disclosure

  • October 5, 2026WARNING listed by EndZone on the group's public leak site

If your organisation is affected

A listing by EndZone means WARNING appeared on a ransomware extortion site and data attributed to it has been published. If this is your organisation, or a supplier you depend on, the priority is to confirm the intrusion and contain it before the window to act closes.

  • Engage your incident-response team and preserve forensic evidence before remediating — do not wipe affected systems first.
  • Force a password reset and revoke active sessions for exposed accounts; rotate any credentials, API keys or certificates that may have been in the stolen data.
  • Assess regulatory notification duties (GDPR, NIS2, sector regulators) — many carry a 72-hour reporting clock from awareness.
  • Monitor for the data appearing on EndZone's leak site and across paste and breach channels, and brief downstream partners who may be exposed through you.

How we know this. Darkfield monitors public ransomware leak sites continuously, archiving every new disclosure and the data later released against the victim. Each entry on this page is sourced from the operator's own publication and cross-checked against complementary OSINT feeds (RansomLook, ransomware.live, RansomWatch). We do not collect or host stolen data — only the metadata, timestamps and screenshots needed to make the public disclosure searchable and accountable. Records here are corrected when the original post is edited, retracted, or merged with another disclosure.