THREATOPS
THREAT OPSThreat News › [EndZone] AT&T posted to leak site

[EndZone] AT&T posted to leak site

medransomware_livePublished 2026-09-18

Ransomware group: EndZone Victim: AT&T Victim website: att.com Sector: Technology Country: US Discovered: 2026-09-18T07:06:21.557117+00:00 Leak-site post: n/a Description: Revenue: $125.6 billion

Initial access was via a CX contractor doing business with AT&T. Access originally used as vehicle for Equipment Changes/Call Forwarding (thanks a lot TORCH patch) - VPN + HVD (both external and internal

Indicators of compromise

Original source: https://www.ransomware.live/