Desk live·
ForensicPost
Ransomware/Telecom/File 24-0417

Frontier Communications Notified 750,000 People After RansomHub Attack

Frontier shut down systems after detecting an intrusion in April 2024 and later notified around 750,000 people. RansomHub claimed the attack and said it held data on more than two million customers.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetFrontier Communications
ActorRansomHub
S. Rosler8 min readConfidence: high2 sources reviewed

Frontier Communications detected unauthorised access in April 2024 and shut down parts of its environment in response. It subsequently notified close to 752,000 people that their information had been taken, including names and social security numbers.

The RansomHub operation claimed the attack and said the material covered more than two million customers, listing names, addresses, dates of birth, telephone numbers, email addresses, social security numbers and credit scores.

Two Figures, One From Each Side

The company notified 750,000. The operation claimed two million. Neither number can be checked from outside, and they are answering different questions: one is who the company could identify and had a duty to write to, the other is what the operation says it holds.

We report both and adopt neither. A notification count is a floor, not a total — it covers the people an organisation could name from what it could reconstruct.

Credit Scores Are An Unusual Field To Lose

The claimed set includes credit scores, which a telecommunications company holds because it ran an affordability check at sign-up.

That is a byproduct of a single decision years earlier, retained afterwards. A social security number paired with a credit score is materially more useful for impersonation than either alone.

How we reported this

Compiled from the company’s notifications and public reporting, listed below. The two million figure and the field list are RansomHub’s claims, not the company’s. Corrections: corrections@forensicpost.com.

Sources
  1. Frontier warns 750,000 of a data breach after extortion threatsBleepingComputer
  2. Cyberattack on telecom giant Frontier claimed by RansomHubThe Record
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary