← Brightspeed

2026 Brightspeed (Connect Holding II) — Crimson Collective claim ~1M+ US ISP customers (Jan)

2026 1.0M records affected Share on X

Data compromised

Alleged names, contact info, addresses, account and partial payment metadata per class-action and news summaries

Technical writeup

In early 2026, a self-styled extortion group publicly attributed to the name “Crimson Collective” claimed to have exfiltrated on the order of more than one million U.S. residential fiber/DSL customer records from Brightspeed (doing business as Connect Holding II LLC in corporate filings), with Malwarebytes, Cybernews, SecurityWeek, Fox News, and regional outlets describing PII, billing, and payment-history claims. Brightspeed issued statements that it was investigating a cybersecurity event; civil litigation and state-level commentary later treated the matter as a major consumer impact story. This entry reflects criminal-forum and press-claimed scope pending final regulatory victim counts.

Root cause

Unauthorized access to or exfiltration from service-provider systems (actor-branded; method under company investigation)

References