Quick Summary
AllegedExecutive Summary
On September 21, 2026, SOCRadar’s Dark Web Monitoring identified that Momentum, a US-based company operating in the business services sector, was listed on the EndZone ransomware group’s dark web portal. The specific nature of Momentum’s operations or data that may attract ransomware actors is not detailed in the provided information, but its US-based presence aligns with the typical targeting patterns of such groups. EndZone has been relatively quiet, claiming only two other victims, AT&T and Accela, in the past 60 days. This limited number of recent claims makes it challenging to establish definitive sector or geographic patterns for the group. However, all known recent victims of EndZone, including Momentum, are based in the United States.
Technical Analysis
A stealer-log query was performed for the domain gomomentum[.]com. The query returned no records, indicating no direct evidence of compromised credentials associated with this specific domain in the queried dataset. It is important to note that this query is paginated and bounded, meaning that the absence of results does not definitively confirm that no compromise has occurred. Credentials could potentially exist under alternate domain variants used by Momentum or within employee personal accounts where corporate credentials may have been reused. Furthermore, records might exist in data feeds not included in this specific query or may have been used and rotated before indexing. Therefore, the null result should be treated as a lack of positive signal rather than confirmation of an unaffected status. With EndZone having claimed only three victims in total, including Momentum, their initial access methods remain unclear. The limited scope of recent activity provides little insight into their typical intrusion vectors. Further monitoring across alternate corporate domains and remote-access infrastructure is recommended to gain a more comprehensive understanding of potential attack paths.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.