2026 Brightspeed (Connect Holding II) — Crimson Collective claim ~1M+ US ISP customers (Jan)
Data compromised
Alleged names, contact info, addresses, account and partial payment metadata per class-action and news summaries
Technical writeup
In early 2026, a self-styled extortion group publicly attributed to the name “Crimson Collective” claimed to have exfiltrated on the order of more than one million U.S. residential fiber/DSL customer records from Brightspeed (doing business as Connect Holding II LLC in corporate filings), with Malwarebytes, Cybernews, SecurityWeek, Fox News, and regional outlets describing PII, billing, and payment-history claims. Brightspeed issued statements that it was investigating a cybersecurity event; civil litigation and state-level commentary later treated the matter as a major consumer impact story. This entry reflects criminal-forum and press-claimed scope pending final regulatory victim counts.
Root cause
Unauthorized access to or exfiltration from service-provider systems (actor-branded; method under company investigation)