{"id":9697,"date":"2026-01-07T10:05:11","date_gmt":"2026-01-07T10:05:11","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/01\/07\/crimson-collective-claims-to-have-disconnected-many-brightspeed-home-internet-users\/"},"modified":"2026-01-07T10:05:11","modified_gmt":"2026-01-07T10:05:11","slug":"crimson-collective-claims-to-have-disconnected-many-brightspeed-home-internet-users","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/01\/07\/crimson-collective-claims-to-have-disconnected-many-brightspeed-home-internet-users\/","title":{"rendered":"Crimson Collective Claims to have Disconnected Many Brightspeed Home Internet Users"},"content":{"rendered":"<p>    Crimson Collective Claims to have Disconnected Many Brightspeed Home Internet Users<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Crimson Collective, an emerging extortion group, claims to have breached U.S. fiber broadband provider Brightspeed, stealing data on over 1 million residential customers and disconnecting many from home internet service.<\/p>\n<p>The group posted screenshots on Telegram detailing the alleged compromise and urging <a href=\"https:\/\/cybersecuritynews.com\/crimson-collective-allegedly-claim-breach-of-brightspeed\/\" target=\"_blank\" rel=\"noreferrer noopener\">Brightspeed employees<\/a> to \u201cread their mails fast.\u201d\u200b<\/p>\n<p>On January 4, 2026, Crimson Collective announced possession of extensive customer datasets from Brightspeed, a major ISP serving rural and suburban areas across 20 states.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjVr5NkPdkmu9ok3Saj0CiPPdsvgdU9SPrqio0pAh3eSstKQItVVni1ajeTv2iHMkC0RgG8zLcifmGFJlxRT1pWMM_UBAiwhfS2eVze5FxchJvSnvVL2uYcqU6ovB8zs4mYFrBxIIZK-LNOFBabmBzoHMHEc65VQBugUTwtrViIFiWTVfSEIx-jfbcMnWmC\/w640-h558\/Bright2.webp?ssl=1\" alt=\"\"><\/figure>\n<\/div>\n<p>The post listed compromised records, including customer master files with full PII such as names, emails, phone numbers, billing\/service addresses, account status, and network details like fiber\/copper\/4G types, bandwidth limits, and geolocation coordinates.<\/p>\n<p>Additional data encompasses payment histories (IDs, amounts, masked card numbers with last four digits, expiry dates, BINs, holder info), appointment records with technician dispatch details, marketing profiles, and suspension reasons.\u200b<\/p>\n<p>The actors released data samples on January 5 as threatened, and claimed a \u201csophisticated attack\u201d enabling user disconnections from ISP service, which was later clarified as home internet, not mobile.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjzqZVAwyOs5igcabb5q_6Fx8A9K2mtWbxn4Wt2TndFa527c9SwHQbKFaOQXLwaHFOtUvhmbbUEOFQCjgBo5qRXnoIoZgmuYBfnaXFMcG1UKli3xZi4e24Xj2zAB-ZS0uzz7TY-95ekPEs7GiGKsSa38xoYX5Ybw4JdjNTDgOeEoJyHgD_hjPi9mjLVay7e\/s16000\/bright1.webp?ssl=1\" alt=\"\"><\/figure>\n<\/div>\n<p>They are offering the full dataset for three Bitcoin (about $276,370), with plans to leak it online within a week if unsold.\u200b<\/p>\n<h2 class=\"wp-block-heading\" id=\"brightspeeds-response\"><strong>Brightspeed\u2019s Response<\/strong><\/h2>\n<p>Brightspeed confirmed it is \u201cinvestigating reports of a cybersecurity event\u201d and takes network security seriously, promising updates to customers, staff, and authorities.<\/p>\n<p>Spokesperson Gene Rodriguez Miller emphasized rigorous threat monitoring but declined to provide specifics on the claims. No evidence of service outages has been widely reported, though the group alleges proactive disruptions.\u200b<\/p>\n<p>Crimson Collective gained notoriety in 2025 for breaching <a href=\"https:\/\/cybersecuritynews.com\/red-hat-confirms-data-breach\/\" target=\"_blank\" rel=\"noreferrer noopener\">Red Hat\u2019s GitLab repositories<\/a>, exfiltrating 570GB of data that later impacted 21,000 Nissan customers\u2019 PII.<\/p>\n<p>They collaborated with <a href=\"https:\/\/cybersecuritynews.com\/scattered-lapsus-hunters-registered-40-domains\/\" target=\"_blank\" rel=\"noreferrer noopener\">Scattered Lapsus$ Hunters<\/a> (ShinyHunters-linked) for extortion and have targeted AWS environments via credential abuse. The group has not disclosed intrusion methods for Brightspeed but hinted at ignored pre-disclosure emails.\u200b<\/p>\n<p>Affected customers face risks of phishing, identity theft, and targeted attacks from exposed PII and partial payment data, though full cards or passwords were not claimed stolen.<\/p>\n<p>Cybersecurity experts urge monitoring accounts and enabling MFA, as the incident highlights vulnerabilities in telecom infrastructure. Federal probes may follow, given Brightspeed\u2019s critical role. As of January 7, no full breach confirmation exists, but samples appear authentic per the researcher\u2019s cross-checks.\u200b<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/crimson-collective-brightspeed-users\/\">Crimson Collective Claims to have Disconnected Many Brightspeed Home Internet Users<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/crimson-collective-brightspeed-users\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Crimson Collective Claims to have Disconnected Many Brightspeed Home Internet Users Crimson Collective, an emerging extortion group, claims to have breached U.S. fiber broadband provider Brightspeed, stealing data on over 1 million residential customers and disconnecting many from home internet service. The group posted screenshots on Telegram detailing the alleged compromise and urging Brightspeed employees [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,156],"tags":[130],"class_list":["post-9697","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-data-breach","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9697"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9697"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9697\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9697"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9697"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9697"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}