Skip to content
Social engineeringContained

Charter Communications (Spectrum) confirms breach after ShinyHunters vishing and extortion

U.S. cable and broadband provider Charter Communications confirmed a data breach after ShinyHunters threatened to leak customer records it said it exported from Charter's Salesforce environment following a voice-phishing attack on an employee's Microsoft Entra account.

Victim
Charter Communications
records
4.9M

On 26 May 2026, Charter Communications, the company behind the Spectrum cable, broadband and mobile brand, confirmed a data breach after the extortion group ShinyHunters threatened to publish stolen data unless it was paid.

What happened

ShinyHunters said it breached Charter on 1 April 2026 through a voice-phishing (vishing) call that compromised an employee's Microsoft Entra account. The group said it used that access to reach Charter's Salesforce instance and export large volumes of consumer and business customer records.

The group claimed around 40 million records, including names, email and postal addresses, phone numbers, phone type, plan information, some customer proprietary network information (CPNI) and support ticket data. Charter disputed the most sensitive part of that claim, telling authorities that no sensitive personal information or CPNI was exfiltrated.

Scale

When the data was leaked, Have I Been Pwned loaded 4,851,517 unique email addresses, far fewer than the group's headline figure. The gap between the attacker's record count and the unique individuals behind it is a recurring feature of ShinyHunters leaks, which count raw CRM rows rather than people.

Why it matters

The Charter breach is part of the 2026 ShinyHunters campaign against SaaS customer databases, which relied on convincing phone calls to employees rather than software flaws. Once a single SSO identity was taken over, the attacker could pull customer data directly from a cloud CRM, bypassing the provider's core network defenses entirely.

Timeline

  1. According to ShinyHunters, the group breaches Charter by voice-phishing an employee and taking over their Microsoft Entra account.

  2. Charter confirms the data breach after ShinyHunters threatens to leak the stolen data unless a ransom is paid.

Sources

  1. bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/charter-confirms-data-breach-after-shinyhunters-extortion-threat/
  2. privacyguides.orghttps://www.privacyguides.org/news/2026/05/29/data-breach-roundup-may-22-28-2026/
  3. haveibeenpwned.comhttps://haveibeenpwned.com/PwnedWebsites#Charter

Related incidents