Ransomware Group EndZone Hits: ATandT
Summary
In the latest cybersecurity news, AT&T — an organization based in US — has fallen victim to a ransomware attack conducted by the group EndZone. This data breach, discovered on 2026-09-18T07:06:21.557117+00:00, underscores the increasing need for proactive cybersecurity defenses as we continue through 2026.
Incident Report
| Attribute | Information |
|---|---|
| Target Organization | AT&T |
| Threat Group | EndZone |
| Summary | Revenue: $125.6 billion
Initial access was via a CX contractor doing business with AT&T. Access originally used as vehicle for Equipment Changes/Call Forwarding (thanks a lot TORCH patch) – VPN + HVD (both external and internal MyDesktop) instances were accessed for a prolonged period without any detection or incident response taking place. Certificates exported from certlm in the VDI + OPUS self installer (automatically joins EP to S1) opened up the door to the VPN. Salesforce data was accessed via a project manager ATTUID + a DirecTV contractor who for some reason had the apps available in Salesforce. AT&T CSO, if you are reading this, you are to contact us ASAP! |
| Date of Breach | 2026-09-18T07:06:20.213947+00:00 |
| Discovery Date | 2026-09-18T07:06:21.557117+00:00 |
| Region | US |
| Target Domain | att.com |
| Business Sector | Technology |
How to reduce your ransomware risk
Most ransomware intrusions start with a stolen password or a phishing email. A few proactive steps sharply cut your exposure:
- phishing simulations — close the gap attackers exploit.
- awareness training — close the gap attackers exploit.
Want to know if you’re already exposed? Run a free scan with the HookPhish data breach checker.
Disclaimer
HookPhish does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.
