← Blog

Momentum Telecom EndZone Claim: 7.5M Users Unverified

Share on X

Unverified claim: around 21 September 2026, the emerging ransomware and extortion group EndZone listed Gomomentum.com / Momentum Telecom on its leak site and alleged that attackers reached a Multi-Service Operator (MSO) diagnostic and provisioning tool, pulled personally identifiable information for more than 7.5 million users across MSO customers, and deleted modem packages for 58,127 U.S. users—leaving those households and businesses without internet until the actor restores service.

Momentum Telecom had not confirmed a breach, outage campaign, or data theft in sources indexed for BreachHistory at catalog time. Everything below about access path, scale, and modem deletions comes from the actor’s leak-site statement as mirrored by trackers such as Ransomware.live, plus secondary write-ups from DeXpose and HookPhish. Treat counts and technical details as extortion marketing until the company publishes a forensic notice or a regulator forces disclosure.

The listing lands in the same early EndZone burst that also named Accela and AT&T that week. For readers following the campaign, see our catalog rows for the Accela EndZone claim and the AT&T EndZone claim. The canonical Momentum record is at breachhistory.com/momentum-telecom/momentum-telecom-endzone2026.

What EndZone says happened

According to the actor statement republished by leak trackers, Momentum is described as a U.S. telecommunications company founded in 2001. The group’s copy pitches the firm as a provider of cloud voice, managed networks, SD-WAN, and Microsoft Teams Phone integration, and even floats a revenue figure. That corporate biography is the attacker’s framing—not an independent audit—and should be read as background color for an extortion post, not as verified due diligence.

The claimed intrusion path is more specific than most leak-site blurbs. EndZone says access came through a compromised Multi-Service Operator diagnostic and provisioning tool used by Momentum. In plain English: MSOs are cable and broadband operators that often share or rely on upstream tools to provision modems, voice lines, and related customer services. If a diagnostic or provisioning console sits upstream of many operators, a break there can look less like “one company’s VPN” and more like a master key for internet and voice packages across markets.

The group further claims that after reconnaissance it found multiple critical vulnerabilities in that tool, that the system controls internet and voice services for large user populations, and that prolonged access went unnoticed until disruptive modem deletions began. It alleges a cat-and-mouse cycle in which defenders revoked access and attackers regained it. Finally, it states that modem packages for 58,127 U.S. users were removed and that restoration is possible only if Momentum management contacts the group.

None of that sequence has been independently confirmed by Momentum in the sources we indexed. Leak-site narratives are written to maximize pressure: big headcount numbers, vivid outage imagery (“families, businesses, students”), and a restore-with-a-click demand. Those rhetorical moves are standard in modern double-extortion and operational-disruption claims. They are not proof.

What “7.5 million” and “58,127 modems” actually mean right now

Two numbers dominate the Momentum Telecom data breach chatter online: more than 7.5 million users’ PII, and 58,127 deleted modem packages. Both are actor claims.

The 7.5 million figure is presented as PII spanning users across MSOs tied to the compromised tool—not necessarily as 7.5 million Momentum-branded retail accounts. That distinction matters. A provisioning platform that serves many operators can hold identity and service records for people who never visited gomomentum.com and may not recognize Momentum as their ISP. If the claim is later confirmed, affected people may hear first from a local cable brand, a business voice reseller, or a municipal broadband partner—not from a single consumer marketing email.

The 58,127 modem figure is sharper and more operational. EndZone is not only threatening a future dump; it is claiming present-tense service sabotage. That style of pressure—break connectivity, then sell restoration—is closer to destructive intrusion and sabotage than to classic “encrypt and wait” ransomware alone. It also creates a phishing goldmine: scammers do not need a real breach to send “your modem was deleted—click to restore” messages the same week a headline circulates.

Until Momentum or a regulator publishes attested counts, BreachHistory records the actor’s 7.5 million figure as an unverified claim in the catalog and keeps the outage number labeled the same way. Do not treat either number as company-confirmed census.

Why a provisioning tool claim should worry telecom operators

Even while this incident remains unverified, the alleged access path is worth understanding on its own. Diagnostic and provisioning systems sit at a dangerous intersection of identity, network configuration, and remote control. They often know which modem MAC addresses map to which subscriber accounts, which voice packages are active, which address a circuit serves, and which support tickets or outage flags are open. In the wrong hands, that is both a privacy problem and a switch that can darken neighborhoods.

Critical vulnerabilities in such tools are not theoretical. Over the last several years, telecom and cable ecosystems have repeatedly shown that management planes—OSS/BSS portals, CPE provisioning APIs, field-tech diagnostic apps, and partner MSO consoles—get less public scrutiny than consumer-facing websites, yet hold more operational power. An attacker who lives inside a provisioning workflow can:

  • Export subscriber identity fields and service inventories at industrial scale
  • Map physical service locations and account hierarchies across partner brands
  • Disable or reassign CPE packages without needing endpoint malware on every household router
  • Re-enter after credential resets if the underlying vulnerability or partner trust path remains open

That last point mirrors EndZone’s alleged “burn access, regain access” story. Whether or not that story is true for Momentum, it is a useful stress test for operators: if your incident response only rotates passwords on a partner tool while the privilege model and patch debt stay untouched, you have treated a symptom.

Readers comparing infrastructure-adjacent incidents may also want the verified-style catalog context around large energy and utility API exposures such as our CenterPoint Energy API record—different sector, same lesson that powerful backend interfaces amplify both data and disruption risk when they fail closed poorly.

Who might be at risk if the claim is real

Because the actor frames exposure as “every MSO” reachable through the tool, risk is not limited to people who think of themselves as Momentum customers.

Residential broadband and voice subscribers

If modem packages were deleted for tens of thousands of U.S. users, those households would notice first as an outage: no internet, failed Wi-Fi, voice that rides the same CPE going silent. Separately, if PII from provisioning databases was copied, typical telecom fields in similar incidents historically include names, service addresses, account numbers, phone numbers, email contacts, and sometimes government ID or payment tokens—though EndZone’s public Momentum statement does not publish a clean field-by-field inventory in the tracker copies we reviewed. Absence of a field list is not evidence those fields were safe; it is simply an unverified claim without a detailed schema dump in the secondary sources cited here.

Small businesses on cloud voice, SD-WAN, or Teams Phone

Momentum’s marketed footprint—cloud voice, managed networks, SD-WAN, Teams Phone—means business tenants could face dual pain: connectivity loss plus exposure of admin contacts, SIP trunk metadata, and directory information that helps follow-on business email compromise. A “your Teams Phone tenant needs re-provisioning” lure is especially plausible after this kind of headline.

MSO partners and their end customers

The claim’s core is partner-tool compromise. Downstream MSOs may inherit both outage tickets and notification duties even if their own corporate networks were never touched. That split responsibility is classic supply-chain failure: the brand customers trust is not always the brand that owned the broken console.

Employees and contractors

The actor statement focuses on user PII and modem packages, not an HR dump. Still, prolonged access to a diagnostic environment can expose internal usernames, ticket notes, and partner credentials. Treat internal accounts as potentially replayable until Momentum says otherwise—again, if and when it confirms anything.

EndZone’s early campaign context

Ransomware.live characterizes EndZone as a new group, with first observed activity around mid-September 2026 and a small victim count in its first days. New brands deserve extra skepticism: some are rebrands, some are affiliates testing leak-site theater, and some inflate claims before any dump appears.

That same week’s Accela and AT&T listings matter less as proof that Momentum was hit and more as pattern recognition. EndZone is presenting itself as willing to name large U.S. brands and to mix data-theft language with access narratives that sound operationally specific (contractor access in one claim, portal and citizen-request volumes in another, MSO provisioning here). Specificity sells. It is also easy to fabricate from public marketing copy and industry jargon.

What this is not: confirmation that a single coordinated campaign successfully breached three unrelated enterprises on a shared exploit. Parallel leak-site posts in one week can share an operator, a copywriter, or nothing but timing. Keep each victim claim in its own evidence bucket.

What Momentum and regulators have said

At indexing time for BreachHistory, we did not locate a Momentum Telecom customer notice, status-page acknowledgment, SEC filing, or state attorney general sample letter confirming this EndZone listing. Absence of a public statement is common in the first hours after a leak-site post and does not by itself prove or disprove the claim.

Regulators may eventually matter if a confirmed breach involves consumer PII at multi-million scale. U.S. telecom and cable incidents can trigger state breach-notification clocks, FCC interest where customer proprietary network information is implicated, and class-action scrutiny when outages coincide with alleged data theft. None of those processes start from a leak-site screenshot alone. They start when a company or investigator attests to unauthorized access and defines the population.

Until that happens, responsible coverage keeps the unverified label in the headline and the first paragraph—not buried under SEO filler.

How to think about phishing after a gomomentum headline

Whether or not EndZone truly offline’d 58,127 modems, the public claim creates a ready-made social-engineering script. Expect messages that look like this:

  • “Your Momentum / local cable modem package was deleted—verify identity to restore service”
  • “EndZone ransom payment portal for affected gomomentum customers”
  • “IT: rotate MSO provisioning credentials using this urgent SSO link”
  • “Teams Phone emergency reprovisioning required for your tenant”

Real outage recovery does not ask you to paste passwords into a Telegram bot, pay cryptocurrency to a stranger, or open a random .html attachment named “modem_restore.” Real support walks you through official apps, printed bill numbers, and known phone numbers you already trust—not ones that arrived in the same SMS that announced the crisis.

What you should do

Action items differ by audience. Keep them concrete.

  1. Residential customers with an active outage: Contact your ISP only through the phone number or app you already used before this news. Ask whether the outage is a known provisioning issue and whether any identity-protection steps are recommended. Do not call numbers from unsolicited texts.
  2. Anyone who recognizes Momentum, a Momentum partner brand, or a local MSO logo on their bill: Watch for official breach mail. Ignore “you are one of 7.5 million” messages that demand immediate payment or remote-access software.
  3. Business admins on cloud voice, SD-WAN, or Teams Phone: Confirm admin MFA, review recent provisioning changes, and restrict who can approve CPE or trunk changes. Document unexplained disconnects with timestamps for your vendor ticket.
  4. MSO and partner security teams: Treat shared diagnostic/provisioning tools as crown-jewel systems. Patch critical flaws, enforce break-glass monitoring, and assume partner compromise can bypass your perimeter. Log deletes and package changes with immutable audit trails.
  5. Identity hygiene for potentially exposed users: If you later receive a confirmed notice listing your data types, freeze credit where SSN or national ID appears, rotate reused passwords, and enable MFA on email first—email is how most “restore modem” scams authenticate fake urgency.
  6. Executives and counsel: Do not negotiate from panic on a leak-site timer. Engage incident response and legal before any contact with an extortion group; paying does not guarantee restoration or deletion of copies.
  7. Journalists and researchers: Cite primary tracker URLs and keep actor counts labeled unverified. Do not launder a leak-site claim into “Momentum confirmed 7.5 million records exposed” without a company or regulator source.

Separating disruption claims from data claims

Modern extortion increasingly blends three products: stolen files, public shaming, and live operational pain. The Momentum listing leans hard on the third. That is strategically smart for attackers because outages create executive escalation faster than a quiet database copy. It is also strategically useful for defenders to measure separately.

A confirmed modem-deletion event without confirmed exfiltration is still a serious integrity and availability incident. A confirmed PII exfiltration without mass outages is still a serious confidentiality incident. EndZone claims both. Independent verification might support one, both, or neither. Readers asking “was I affected” should wait for population definitions from the companies that actually hold the billing relationship—not from screenshots of an onion site.

If you are trying to triage personal risk today, use a simple filter: Did your internet fail in a way your provider attributes to account provisioning? Did you receive an official letter naming data elements? If both answers are no, you are watching a news story, not a personal forensic finding. Stay alert for phishing; do not invent certainty.

How this fits telecom PII risk in 2026

Telecom PII is uniquely valuable because it bridges digital identity and physical location. Account numbers unlock support-desk impersonation. Service addresses support stalking and burglary targeting. Phone numbers and emails fuel SIM-swap and credential-stuffing chains. When attackers also claim control of modem provisioning, the story stops being only about privacy and becomes about whether connectivity itself can be held hostage.

That combination is why an unverified Momentum Telecom EndZone ransomware claim still deserves a full public explanation. People need language for what was alleged, what remains unknown, and what scams look like while the company stays silent. Silence is not confirmation. It is also not a reason to shrug when 7.5 million and fifty-eight thousand are circulating in search results.

Compare that posture with older, fully documented carrier breaches where companies eventually published field lists and credit-monitoring offers. Those post-mortems teach what good disclosure looks like: dates of detection and containment, systems involved, data elements, geographic scope, and concrete customer steps. The EndZone Momentum post, as mirrored so far, offers none of that attestation. It offers a narrative optimized for leverage.

Canonical record and sources

BreachHistory’s living catalog entry for this incident is 2026 Momentum Telecom — EndZone claim (unverified). We will update that row if Momentum confirms, denies with evidence, or a regulator publishes an attested notice. Related EndZone-week listings for context: Accela and AT&T.

Primary and secondary sources used for this article:

Bottom line for searchers landing on “Momentum Telecom data breach,” “gomomentum,” “EndZone ransomware,” or “modem provisioning” queries: as of indexing, this is an unverified leak-site claim of telecom PII at multi-million scale plus alleged U.S. modem deletions. What to do after reading it is straightforward—use official channels only, harden provisioning and MFA if you operate in this stack, and wait for company attestation before treating 7.5 million as a finished fact.