Skip to content
[ENDZONE] – Ransomware Victim: AT&T

[ENDZONE] – Ransomware Victim: AT&T

Redpacketsecurity admin September 18, 2026

Verification alert Listings attributed to ENDZONE have been reported as including unverified or fabricated victim claims. Treat this post as unconfirmed until corroborated with independent evidence. See further information here: BankInfoSecurity

See further information here: BankInfoSecurity

NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating to the content should be directed at the attackers, not RedPacket Security. This blog is an editorial notice informing that a company has fallen victim to a ransomware attack. RedPacket Security is not affiliated with any ransomware threat actors or groups and will not host infringing content. The information on this page is automated and redacted whilst being scraped directly from the ENDZONE Onion Dark Web Tor Blog page.

AI Generated Summary of the Ransomware Leak Page

On September 18, 2026, the ransomware group EndZone published a post alleging that AT&T, a U.S.-based technology company, had been compromised. Because no separate compromise date is provided, September 18, 2026, should be treated as the post date rather than the confirmed date of intrusion. The post claims that initial access was obtained through a customer-experience contractor working with AT&T and that the access remained available for an extended period without detection or incident response. The attackers also assert that AT&T has annual revenue of approximately $125.6 billion. According to the allegation, the intruders accessed virtual desktop and VPN environments and used exported certificates and an internal software installer to facilitate further access. The post also claims that Salesforce information was accessed through compromised user and contractor accounts with application permissions. These assertions describe unauthorized access to corporate systems and business data, but the post does not specify whether files were encrypted, identify a confirmed volume of exfiltrated information, or provide a ransom demand. No screenshots, images, downloadable files, or external links are included on the page.

On September 18, 2026, the ransomware group EndZone published a post alleging that AT&T, a U.S.-based technology company, had been compromised. Because no separate compromise date is provided, September 18, 2026, should be treated as the post date rather than the confirmed date of intrusion. The post claims that initial access was obtained through a customer-experience contractor working with AT&T and that the access remained available for an extended period without detection or incident response. The attackers also assert that AT&T has annual revenue of approximately $125.6 billion.

According to the allegation, the intruders accessed virtual desktop and VPN environments and used exported certificates and an internal software installer to facilitate further access. The post also claims that Salesforce information was accessed through compromised user and contractor accounts with application permissions. These assertions describe unauthorized access to corporate systems and business data, but the post does not specify whether files were encrypted, identify a confirmed volume of exfiltrated information, or provide a ransom demand. No screenshots, images, downloadable files, or external links are included on the page.

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.

Extracted Entities

Attack Types (1)

Companies (2)

Ransomware Groups (1)