ShinyHunters Breach Charter Communications: 4.9M Accounts Exposed
The ShinyHunters extortion gang has breached Charter Communications, exposing 4.9 million customer and business accounts. Consequently, the telecom giant confirmed the incident while disputing the severity of the stolen data.
Charter Communications is one of the largest broadband and cable providers in the United States. It operates the Spectrum brand and serves more than 32 million customers across 41 states. Therefore, any security incident at this scale demands immediate attention from both consumers and enterprise security teams.
What Happened: ShinyHunters Breaches Charter Communications via Vishing Attack
On April 1, 2026, threat actors compromised a Charter Communications employee’s Microsoft Entra account through a voice phishing (vishing) attack. Moreover, the ShinyHunters extortion group claimed responsibility and stated they leveraged this access to infiltrate the company’s Salesforce instance.
The attackers asserted they extracted 42 million records containing consumer and business customer data. However, Charter spokespersons denied that sensitive personal information or customer proprietary network information (CPNI) was stolen. Instead, the company emphasized that only sales tools used for current, past, and prospective business customers were impacted.
After Charter refused to pay the ransom, ShinyHunters published the stolen data on their dark web leak site. Furthermore, Have I Been Pwned analyzed the leaked dataset and confirmed that 4.9 million unique accounts were exposed.
Technical Details of the Charter Communications Data Breach
The attack chain began with social engineering. ShinyHunters operators called a Charter employee and convinced them to surrender credentials or approve an authentication request. Thus, the attackers gained access to the employee’s Microsoft Entra identity.
From there, the threat actors navigated to the company’s Salesforce environment. Salesforce is widely used for customer relationship management. Therefore, a compromised instance can yield extensive contact and account data. The attackers claimed they harvested names, email addresses, physical addresses, phone numbers, phone types, plan information, and support ticket data.
Approximately 85,000 records originated from an internal employee directory. In addition, these records included job titles alongside standard contact details. ShinyHunters has systematically targeted Salesforce customers over the past year, breaching hundreds of organizations and claiming billions of stolen records.
Business and Operational Impact
The breach carries significant consequences for both consumers and enterprises. Although Charter states no sensitive CPNI was stolen, the exposed data still creates risks. For example, the leaked information includes:
- 4.9 million unique email addresses tied to Charter and Spectrum accounts
- Names, phone numbers, and physical addresses suitable for targeted phishing
- Approximately 85,000 employee records with job titles, enabling corporate impersonation
- Business customer sales records that reveal service plans and support history
Moreover, ShinyHunters has demonstrated a pattern of re-extorting victims or selling data to other criminals even after initial publication. The FBI explicitly advises victims not to pay ransoms, since payment cannot guarantee data deletion.
Reputational damage is another concern. Charter serves millions of households and thousands of business clients. Therefore, trust erosion can lead to customer churn, regulatory scrutiny, and increased support costs.
Mitigation and Recommendations
Organizations and individuals should act now to reduce exposure from this incident.
Immediate Actions for Affected Consumers
- Monitor bank and credit card statements for unusual activity.
- Enable two-factor authentication on all accounts, especially those using the exposed email address.
- Watch for phishing emails or SMS messages impersonating Charter, Spectrum, or related services.
- Consider placing a fraud alert or credit freeze with major bureaus.
Immediate Actions for Enterprises
- Audit Salesforce and CRM access logs for unauthorized queries or exports.
- Enforce phishing-resistant MFA such as FIDO2 security keys for all identity providers.
- Review vishing awareness training and test employee response to social engineering calls.
- Segment CRM data so compromised credentials cannot access entire customer datasets.
Long-Term Defensive Measures
- Implement data loss prevention (DLP) policies on Salesforce and other cloud SaaS platforms.
- Conduct regular red team exercises that include vishing and social engineering simulations.
- Subscribe to dark web monitoring services to detect leaked credentials early.
Bottom line: Even “non-sensitive” data breaches create downstream risk. Attackers can weaponize names, emails, and addresses into convincing phishing lures that lead to account takeovers or fraud. Patch the human layer first.
Incident Summary
| Incident: | Charter Communications / Spectrum Data Breach by ShinyHunters |
| Affected Systems: | Salesforce CRM instance, Microsoft Entra identity platform |
| Disclosure Date: | May 29, 2026 |
| Patch Status: | N/A — incident response and investigation ongoing |
| Records Exposed: | 4.9 million customer and business accounts; ~85,000 employee records |
| Threat Actor: | ShinyHunters extortion gang |
| Attack Vector: | Voice phishing (vishing) leading to compromised Microsoft Entra account |
| Data Types: | Names, email addresses, phone numbers, physical addresses, job titles, plan information, support ticket data |
References
- Bill Toulas, “Charter Communications data breach affects 4.9 million accounts,” BleepingComputer, May 29, 2026, https://www.bleepingcomputer.com/news/security/charter-communications-data-breach-affects-49-million-accounts/, accessed May 31, 2026.
- Have I Been Pwned, “Charter Data Breach,” https://haveibeenpwned.com/Breach/Charter, accessed May 31, 2026.
- FBI Internet Crime Complaint Center, PSA I-052615-001, “FBI Advises Against Paying Ransom to ShinyHunters Extortion Group,” May 15, 2026.
- Sergiu Gatlan, “ShinyHunters claims ongoing Salesforce Aura data theft attacks,” BleepingComputer, April 2026.
SEO Information
| SEO Title: | ShinyHunters Breach Charter Communications: 4.9M Accounts Exposed |
| SEO Slug: | shinyhunters-charter-communications-data-breach-4-9-million |
| Meta Description: | ShinyHunters breached Charter Communications via vishing, exposing 4.9 million accounts. Learn the attack details, impact, and protective steps for consumers and enterprises. |
| Focus Keyphrase: | Charter Communications data breach |