Skip to content

Rainbow Communications Cybersecurity Incident

Summary

Rainbow Communications logo

Rainbow Communications reported a Nov. 16, 2025, cybersecurity event that interrupted hosted business and home phone services in northeast Kansas. The company said all affected services were restored by Nov. 19; INC Ransom later claimed the attack and data theft, which Rainbow has not verified.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.
  • Incident end:
    ? Confirmed or defensibly assessed end of material operational disruption or incident activity.

Primary victim organization

Organization types

Critical infrastructure sector

Incident characteristics

Assessments

Attack mechanisms

  • Unknown cyber mechanism

    The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.

Data impacts

  • Unknown data impact

    The incident is cyber-related, but available evidence does not establish whether or how data was affected.

Operational impacts

  • Phone service disruption

    Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.

  • Third-party service disruption

    The incident materially affected services delivered by or through a vendor, managed service provider, contractor, partner, or other third party.

Extortion indicators

  • Leak-site listing

    The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.

  • Data sample published

    The actor published or shared a sample of allegedly stolen victim data to substantiate the extortion claim.

Incident narrative

Analyst assessment

Rainbow Communications reported a network interruption beginning Nov. 16, 2025, and later described it as a cybersecurity event. It disconnected parts of its network as a precaution and brought in outside specialists. Its own wording supports a confirmed cyber assessment, but it did not publicly identify the attack mechanism or confirm ransomware.

Operational significance

Hosted PBX and residential phone customers across northeast Kansas experienced service interruptions. Rainbow’s own hosted phone system was also affected, prompting a temporary help desk number. Most internet service remained available, though some customers reported connectivity problems. The Everest location marks the company headquarters; the service-area record represents its regional utility footprint and does not imply every served address lost service. The precise service polygon is not established by the reviewed material, so the overlay requires mapping review.

Later claim

Comparitech reported on Dec. 10 that INC Ransom claimed responsibility and alleged theft of 200 gigabytes of accounting, personnel and customer information. The group reportedly posted sample images. Rainbow has not verified the claim, data theft or a ransom demand. The group attribution is recorded as a low-confidence claim.

Current status

A company update quoted by Comparitech said all services affected by the cyber event had been fully restored by Nov. 19. This supports a resolved operational status, while the data investigation and actor claim remain separate unresolved questions.

Confidence and uncertainty

Confidence is high in the documented phone disruption and restoration. Ransomware involvement is possible based on the later actor claim but unconfirmed by the provider. The initial access method, precise affected-customer count, confirmed data impact, payment status and final service-boundary polygon remain unknown. A fresh claim-index search did not return a matching listing; the actor claim remains supported by contemporaneous secondary reporting.

Threat actor and claim

Listed as: Rainbow CommunicationsSource: otherPublished:

Claim details

INC Ransom claimed the provider and 200 GB of data theft; the provider has not verified the allegation.

Organizations involved

Impacted locations

Sources

Kansas telecom cyber event disrupts Rainbow phone lines

Rural broadband provider Rainbow Communications is working to restore Hosted PBX and home phone service across northeast Kansas after a cybersecurity event began disrupting parts of its network Sunday, Nov. 16, 2025.

Ransomware gang says it hacked Kansas broadband provider Rainbow Communications

Rainbow said all services impacted by the recent cybersecurity event had been fully restored by Nov. 19. INC Ransom later claimed it stole 200 GB of accounting, HR and customer data; Rainbow did not verify that claim.

See something that needs correction?

Signed-in members can report an error, update, or missing source.