Description

In February 2025, Communications Data Group (CDG), an Illinois-based telecom SaaS company, suffered a ransomware attack that compromised the personal data of 42,518 Duo Broadband customers, one of its clients. There were names, addresses, birthdates, and Social Security numbers exposed in the breach.. CDG, which offers billing and software services to telecommunications firms, discovered the incident on February 13 when intruders tried to spread ransomware and demand payment. The ransomware group Qilin subsequently claimed responsibility for the attack in March 2025 and placed CDG on its data leak website, although CDG has not confirmed this notification. The attack indicates the persistent cybersecurity threat to US utility and telecommunications providers. In addition to Agenda, Qilin is a ransomware-as-a-service gang based in Russia that uses phishing attacks to access systems. This attack is significant as the first confirmed ransomware attack on a US utility in 2025, and among the biggest since 2023. Other utility breaches linked to Qilin in the past include Aiken Electric Cooperative in 2024. These kinds of attacks have the potential to disrupt billing and operations and lead to stolen data being used in identity fraud if ransoms are not paid. Impacted businesses would be advised to prioritize multi-factor authentication, employee cybersecurity training, and routine security audits. Organizations in critical infrastructure industries, particularly utilities, need to enhance ransomware resilience and incident response planning to reduce future risk.