endzone

Active
2 victims named on the leak site
2 in the last 30 days
2 in the last 12 months
Sep 2026 first victim we recorded
Sep 21, 2026 most recent victim posted
1 leak site tracked

Data as of September 21, 2026.

What industries endzone targets

Sector identified for all 2 victims.

Government1
Telecommunications1

Where the victims are located

Country identified for all 2 victims.

United States2

Every endzone victim

VictimSectorCountryPosted
Accela accela.comGovernmentUnited StatesSep 21, 2026
AT&T att.comTelecommunicationsUnited StatesSep 21, 2026

Browse recent data breaches for more.

endzone leak site

The address we've seen endzone publish victims from. Any .onion address needs the Tor Browser.

  • endzonezgz3sqzmtqg4acp4z7ao7xc6vunfhezjsnfqrm2ksudsredyd.onion

endzone questions

Is endzone still active?

Yes. endzone posted its most recent victim on September 21, 2026. That's 2 victims in the last 30 days.

How many victims has endzone claimed?

endzone has named 2 victims on its leak site since we started tracking it. That counts organizations, not leaked files. A single victim often accounts for thousands of published files.

When did endzone first appear?

The first victim we recorded for endzone was posted on September 21, 2026. That's when the group entered our collection, which isn't necessarily when it started operating.

Has endzone already got your credentials?

Check whether your employees' logins have leaked on the dark web before they're exploited.

Check your exposure →

Continuous dark web monitoring alerts you when your company's data shows up, whether that's employee credentials or files published after an attack.