« All news

New threat group

Endzone, a new extortion group with four claims since September

A previously unknown actor calling itself Endzone began listing victims on its leak site on 18 September 2026 and has posted four claims so far, including telecoms, technology and professional services firms, mostly in the United States.

What happened

An extortion group operating under the name Endzone has been active since 18 September 2026. According to RansomLook tracking, it has published four entries on its leak site since that date.

The reviewed listings involve organisations in telecommunications, technology and professional services, mostly based in the United States: AT&T and Accela (both posted on 18 September), and Momentum and eTeam Inc. (both on 26 September). No country is recorded for Momentum.

It is important to stress that these are claims made by the group itself. Based on the available information, there is no independent confirmation of the incidents, nor of the volume or nature of any data allegedly obtained. Listings of this kind frequently include exaggerated, outdated or third-party information.

Who the group is

For practical purposes, Endzone is an emerging actor. Its first publication is only weeks old, it does not appear in reference databases such as MISP Galaxy or MITRE ATT&CK, and no links to known ransomware families or extortion brands have been documented.

That means there is still no reliable information about its initial access vectors, tooling or operating model (encryption, data theft, or both). Any attribution or technical detail circulating in these early weeks should be treated with caution: new groups often reuse code and access bought from third parties, and their activity can disappear as quickly as it appeared.

Why it matters

The profile of the claimed victims points to technology, telecom and service providers, that is, organisations that hold data and access belonging to many customers. An incident at a supplier can have knock-on effects across its supply chain, even for companies that are not the direct victim.

What organisations can do

In the absence of specific indicators, the sensible response is to reinforce the controls that mitigate most extortion intrusions:

Enforce multi-factor authentication on VPNs, remote access, email and administrative portals, and review any accounts still without MFA. Prioritise patching of internet-facing devices such as VPNs, firewalls and file transfer servers. Reduce the exposed attack surface and review third-party and supplier access. Keep isolated, immutable backups and test restoration. Monitor for anomalous logins, creation of privileged accounts and unusual outbound data volumes. Revisit incident response and communication plans, including GDPR notification duties.

If your organisation works with any of the named providers, the prudent step is to request official information through the usual channels and to rotate shared credentials and integrations if an incident is confirmed.

About the group: Endzone

Claims are published by the criminal groups themselves and are unverified until the organisation or the press confirms them. Names of natural persons (sole traders, individual professionals) are anonymised under the GDPR. We never link to leak sites or stolen data. To request the removal or anonymisation of an entry, contact the site administrator.