← Back to feed
Breaches & RansomwareEmerging1 sourceSep 18, 2026 Β· 07:06via Ransomware.live

πŸ΄β€β˜ οΈ Endzone has just published a new victim : AT&T

Brief

Revenue: $125.6 billion

Initial access was via a CX contractor doing business with AT&T. Access originally used as vehicle for Equipment Changes/Call Forwarding (thanks a lot TORCH patch) - VPN + HVD (both external and internal MyDesktop) instances were accessed for a prolonged period without any detection or incident response taking place.

Certificates exported from certlm in the VDI + OPUS self installer (automatically joins EP to S1) opened up the door to the VPN. Salesforce data was accessed via a project manager ATTUID + a DirecTV contractor who for some reason had the apps available in Salesforce. AT&T CSO, if you are reading this, you are to contact us ASAP!

Read more on Ransomware.live→