Brightspeed, a major U.S. fiber broadband provider operating across 20 states, has reportedly suffered a significant cyberattack attributed to the threat group Crimson Collective. The attackers claim to have gained unauthorized access to Brightspeed's systems, exfiltrating sensitive data including personally identifiable information (PII) of both customers and employees. The group provided samples of the stolen data to cybersecurity researchers as proof of the breach, a tactic increasingly used by threat actors to pressure organizations and bolster their criminal reputation. The incident is notable due to Brightspeed's role as a critical infrastructure provider, serving millions of homes and businesses, and highlights a growing trend of attacks targeting telecommunications and broadband companies.
Brightspeed has acknowledged the breach claims and stated that it is actively investigating the incident, emphasizing its commitment to network security and the protection of customer and employee information. The Crimson Collective alleges that the stolen data includes customer account details, addresses, user account information, payment history, some payment card data, and appointment records, potentially affecting over one million residential users. The group has threatened to release a sample of the data if their demands are not met. This breach follows previous high-profile attacks by Crimson Collective, including incidents involving Red Hat and Nissan, indicating a pattern of targeting large organizations for data theft and extortion.

See the actors and campaigns active against you right now.
4 events from the most recent confirmed update back to the earliest known activity.
The group later claimed it had disconnected some Brightspeed home internet users in addition to stealing customer data. Brightspeed confirmed only that an investigation was ongoing and did not verify the alleged service disruptions.
Crimson Collective posted alleged proof of the breach, including data samples, and offered the full dataset for sale for three bitcoin. The group also threatened to release the data within a week if it was not purchased.
Brightspeed said it was investigating the breach claims, taking the matter seriously, and working to notify affected parties and authorities as more information became available. The company had not confirmed the full scope of the alleged compromise.
The extortion group Crimson Collective claimed it breached Brightspeed and stole data tied to more than 1 million customers. Reported stolen information included PII, account details, payment history, appointment records, and some payment card data.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcego.theregister.com
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.