When a cloud voice or managed-network provider lands on a ransomware leak-site tracker, the risk is not just “their IT problem”—it is your phones, Teams calling, and the BA / vendor relationship that keeps dental chairs, medical clinics, and production floors connected. On September 21, 2026, DeXpose reported that the EndZone ransomware group claimed an attack against Momentum (gomomentum.com), a U.S. telecommunications company that markets cloud voice, managed networks, SD-WAN, and Microsoft Teams Phone integration.
EndZone’s published statement—as relayed by DeXpose—alleges access via a compromised multi-service operator (MSO) diagnostic/provisioning tool, alleged PII exposure, and alleged removal of modem packages for about 58,127 users, with a request that the company contact the actors. Those operational numbers and access claims are threat-actor assertions, not independently verified facts. As of our sources, we have no Momentum company confirmation of scope, encryption, outage, PII inventory, or payment—so we treat this strictly as a leak-site / aggregator claim.
For dental and medical practices, exhibit and fabrication shops, and other SMBs that outsource cloud voice or connectivity, the useful lesson is vendor and business-associate continuity—not inventing a confirmed telecom outage Momentum has not published.
What aggregators report—and what they do not
Public facts from DeXpose: Momentum / gomomentum.com; claimed by EndZone; date reported Sept. 21, 2026; actor statement describing alleged MSO-tool access, alleged PII exposure, and alleged modem-package removals for ~58,127 users. Aggregators republish actor language; they do not equal a verified customer-impact inventory. We do not have company-confirmed breach scope, outage map, PII dump, or payment. Do not present actor figures as settled fact.
Practices and shops share a dependency pattern: front-desk softphones and Teams Phone next to EHR or production scheduling, vendor portals for number porting and call routing, and shared credentials that become painful the moment a headline hits—especially when attackers recycle the story into fake “provider recovery” calls.
Why dental, medical, and production SMBs should treat this as their drill
Chair time, patient callbacks, and install coordination do not pause for a tracker post. Organizations that lean on a single voice vendor without MFA on vendor portals, without a documented failover (cell bridge, secondary SIP trunk, or temporary call-forward), and without a BA inventory inherit the headline as scam and continuity risk—even when the named telecom firm is not your provider.
Post-headline phishing is predictable: spoofed “Momentum support,” “Teams Phone outage,” or “modem restore” messages referencing EndZone. Assume attackers will recycle the story against practices and shops that use any cloud voice vendor. Ask: if inbound voice were degraded for a day, how would you still take appointments and spot fake recovery calls?
Clear takeaway
Treat the EndZone leak-site claim against Momentum (gomomentum.com) as a vendor and BA continuity drill for dental, medical, exhibit/fab, and general SMBs that outsource cloud voice or managed networks—require MFA on vendor portals, document voice failover, inventory business associates with access to call routing and directories, and brief staff against post-headline phishing—without presenting actor claims about PII counts, modem removals, or access paths as independently verified facts, and without inventing company-confirmed scope or payment.
Actions to take this week
- Require MFA on every voice/connectivity vendor portal (admin, number porting, Teams Phone admin, SD-WAN)—password-only shared logins remain the cheapest path onto your call path.
- Document a voice contingency: temporary call-forward to cell, secondary trunk or softphone, and a one-page script for front desk if primary cloud voice fails.
- Inventory business associates and vendors with access to directories, call recordings, or patient/client contact lists—and confirm who gets notified if a BA headline appears.
- Segment vendor remote access where practical: unique accounts, time-bounded sessions, and a revoke path that does not depend on the vendor’s own help-desk email thread.
- Brief staff on post-headline phishing: unexpected links about “the EndZone / Momentum claim,” secrecy demands, or urgent wire requests are red flags; verify via a known phone number, not the email thread.
Brotherly Technology helps dental and medical practices, exhibit and experiential fabrication shops, and other SMBs across Rome, Northwest Georgia, metro Atlanta, and our TN/AL/NY footprint turn telecom cyber headlines into a short vendor-continuity review—without inventing threat details a named company has not confirmed. The EndZone claim against Momentum, as reported by DeXpose on Sept. 21, 2026, is a timely reminder to run that drill now.
Sources:
- DeXpose — EndZone / Gomomentum.com — Date reported Sept. 21, 2026; republishes EndZone actor statement (alleged MSO-tool access, alleged PII exposure, alleged modem-package removals for ~58,127 users)—treat as threat-actor claims, not independently verified.