THREAT ACTOR
ENDZONE_
ActiveENDZONE is a ransomware operator tracked through its public data-leak infrastructure. The group operates under the double-extortion model that defines the modern ransomware ecosystem: file encryption combined with the threat of stolen-data publication on a public leak site. It continues to post fresh victim claims as part of an ongoing extortion campaign.
For Ransomnews editorial coverage of ENDZONE, including incident write-ups, attribution notes and additional context, see the Threat Groups archive or run a site search.
Victims by year
- 2026 6
Leak site mirrors
1 mirror tracked, 1 currently reachable. These are criminal-infrastructure URLs; links are deliberately not provided.
-
endzonezgz3sqzmtqg4acp4z7ao7xc6vunfhezjsnfqrm2ksudsredyd.onionendzone snapshot · 2026-10-08 08:19
Recent victims
The 50 most recent victims claimed by ENDZONE. Total in the index: 6.
| Date listed | Victim | Description |
|---|---|---|
| 2026-10-06 | Philander Smith University | Philander Smith University is a private, historically Black liberal ar… |
| 2026-10-05 | WARNING | This is what happens when you ignore us or go ghost. Momentum Telecom … |
| 2026-09-26 | eTeam | eTeam Inc. is a privately held global workforce solutions and business… |
| 2026-09-26 | Gomomentum.com | Momentum is a telecommunications company founded in 2001 that provides… |
| 2026-09-18 | Accela.com | Accela is a comprehensive cloud based software platform used by state … |
| 2026-09-18 | AT&T | Initial access was via a CX contractor doing business with AT&T. Acces… |