Low Unverified

AT&T Ransomware Claim by EndZone - Sept 2026

By Yazoul AI · automated

Unverified dark web claim. This report is based on a post observed on a dark web forum. Yazoul Security has not independently verified the authenticity of this claim.

Claim Summary

On or around September 18, 2026, a ransomware group calling itself EndZone allegedly listed AT&T, the US telecommunications and technology giant, on its dark web leak site. According to the threat actor’s post, the claimed breach involved access obtained through a customer experience (CX) contractor doing business with AT&T. The group claims the intrusion went undetected for a prolonged period and that it accessed VPN infrastructure, VDI environments, and Salesforce data. The actor also claims to have referenced AT&T’s Chief Security Officer directly in its post, demanding contact.

No data volume was disclosed. The group cited AT&T’s revenue of $125.6 billion, a figure consistent with public financial reporting, which is a common tactic used by ransomware operators to signal the perceived value of a victim. This claim has NOT been independently verified by Yazoul Security or any third party.

Threat Actor Profile

EndZone is a relatively low-profile ransomware operation with no known public research, no documented victim count, and no established toolset attributed to it by external security researchers. This lack of a verifiable track record is a significant credibility concern. Established groups typically accumulate OSINT coverage, MITRE ATT&CK mappings, and analyst reporting over time. EndZone’s absence from public research means we cannot confirm prior successful intrusions, negotiate behavior, or data leak reliability.

The group’s claim references specific technical artifacts, including certificates exported from certlm, an “OPUS self installer,” SentinelOne (S1) endpoint enrollment, and Salesforce application access via an AT&T project manager ATTUID. These details, if genuine, suggest familiarity with enterprise identity and endpoint tooling. However, ransomware groups frequently recycle or fabricate technical jargon to appear credible. No YARA rules or detection signatures specific to EndZone are publicly available at this time. Organizations should rely on general ransomware detection guidance rather than actor-specific indicators.

Alleged Data Exposure

The actor claims initial access originated with a CX contractor and was allegedly used for equipment changes and call forwarding activity. The group further claims that VPN and HVD (MyDesktop) instances, both external and internal, were accessed without triggering detection or incident response. It also alleges that certificates were exported from certlm within a VDI environment and that Salesforce data was accessed via a project manager ATTUID and a DirecTV contractor account.

No data samples, file listings, credentials, or proof-of-breach artifacts have been publicly released or verified. The claim of “prolonged” undetected access is a common pressure tactic and should be treated with skepticism. The mention of a specific internal patch name (“TORCH”) and tooling may be accurate, exaggerated, or entirely fabricated.

Potential Impact

If the claim were substantiated, the alleged exposure of VPN credentials, exported certificates, and Salesforce records could pose significant risk to AT&T’s internal network and customer-facing systems. Call forwarding and equipment change capabilities, if abused, could enable SIM-swap-adjacent fraud or account takeover. However, at this stage, there is no confirmed evidence of data exfiltration, customer impact, or operational disruption. AT&T has not publicly confirmed the claim.

What to Watch For

  • Any official statement from AT&T confirming or denying the incident.
  • Publication of data samples by EndZone, which would raise credibility.
  • Independent researcher analysis of the group’s infrastructure and prior claims.
  • Reports of call forwarding abuse, SIM-related fraud, or Salesforce anomalies affecting AT&T customers.
  • Whether EndZone escalates to double extortion or direct victim negotiation.

Disclaimer

This report is based solely on an unverified claim published by a ransomware group on its leak site. Yazoul Security has NOT independently confirmed the breach, the data exposure, the attack vector, or the involvement of any named contractor or individual. Ransomware groups routinely exaggerate, misrepresent, or fabricate claims to pressure victims into payment. Nothing in this report should be treated as fact. Organizations should monitor official channels for confirmation.

Share:

Never miss a threat intelligence alert

Get real-time security alerts delivered to your preferred platform.

Related Claims

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.