Charter Data Breach Exposes 4.9 Million Customer Accounts

Extortion gang ShinyHunters claims responsibility for April 1st vishing attack that accessed Salesforce data.

By Byte-Pulse Newsroom·AI-augmented editorial system·May 29, 2026·3 min read
Serhat Er — Founder & Editor-in-ChiefEdited bySerhat Er·Founder & Editor-in-Chief
Updated Aug 27, 2026
Charter Data Breach Exposes 4.9 Million Customer Accounts
Byte-Pulse original cover. Source story: BleepingComputer.

Charter Communications, the U.S. telecom giant behind the Spectrum brand, confirmed a data breach. It exposed personal info from nearly 5 million customer accounts. The incident happened in early April. The extortion gang ShinyHunters says it was a voice phishing (vishing) attack.

The Attack Vector

ShinyHunters claims the breach started April 1st. Attackers compromised an employee's Microsoft Entra account. They used a vishing scheme. This initial access reportedly let them into Charter's Salesforce instance. Salesforce is a popular customer relationship management platform. The gang says they stole 42 million records. That’s a lot. It included names, email addresses, physical addresses, phone numbers, plan details, and some customer proprietary network information (CPNI).

Charter serves over 32 million customers across 41 U.S. states. They initially said no sensitive personal info or CPNI was taken. But the data breach service Have I Been Pwned looked at the data ShinyHunters leaked. They confirmed it impacted 4.9 million unique accounts. Exposed data included names, email addresses, phone numbers, and physical addresses. About 85,000 records, apparently from an internal employee directory, also had job titles.

The Ransom Demand and Leak

ShinyHunters demanded a ransom from Charter. They wanted the stolen data back and destroyed. Charter refused. So, the cybercrime group leaked the compromised info on their dark web site. Byte-Pulse asked Charter for comment about the difference between their initial statement and the gang's CPNI claims. We were just directed back to the company's original statement.

"No sensitive personal information (PI) or customer proprietary network information (CPNI) data was exfiltrated by the threat actor as a result of recent activity," Charter told BleepingComputer.

This incident adds to ShinyHunters' history. They've targeted Salesforce customers before. Over the past year, the group has been linked to many breaches worldwide. They claim to have stolen billions of records using similar attacks.

Context and Impact

This breach shows the ongoing threat from sophisticated social engineering attacks. Even big telecom companies aren't immune. The FBI recently advised victims of ShinyHunters not to pay ransom demands. They say payment doesn't guarantee data deletion. It might even lead to more extortion or sales to other criminals.

Charter Communications is a big player in the U.S. telecom market. They provide internet, mobile, video, and voice services. A breach this size can still impact customers. Even if Charter says sensitive data wasn't compromised. Identity theft, targeted phishing, and spam all increase when personal contact info is leaked.

The FBI recently advised ShinyHunters' victims not to give in to the gang's ransom demands. They'd previously warned that doing so can't guarantee threat actors won't try to sell the stolen data to other cybercriminals or extort them again.

What's Still Unclear:

  • Did CPNI data get exfiltrated? Have I Been Pwned confirmed contact details for 4.9 million accounts were exposed. But confirmation on whether any CPNI data was actually stolen is still missing. Charter sticks to its original stance.
  • How exactly did the vishing work? The specific details of the vishing attack and how the employee's Microsoft Entra account was compromised aren't public.
  • What's the full scope of Salesforce data? ShinyHunters claimed 42 million records. But the complete inventory of data within the compromised Salesforce instance isn't detailed.

Why This Matters:

Charter's data breach highlights the critical need for strong cybersecurity. Defenses must counter evolving social engineering tactics. The incident serves as a stark reminder. Even with solid technical safeguards, human vulnerability is a primary attack vector. It can expose millions of customers to more risks.

Discuss this story

Got a take, a correction, or a follow-up tip? Reply where you read — we read everything.

Found an error? File a correction at /corrections. Substantive corrections are logged publicly.

#charter#data breach#shinyhunters#salesforce#vishing#cybersecurity
Get the 5 tech stories worth your time — 3× a week

One short email. The most important Security news, fact-checked, no fluff. Free, unsubscribe anytime.

More from Security

About the author
AI-augmented editorial system

The Byte-Pulse Newsroom is the editorial system that produces Byte-Pulse's daily tech news coverage. Each story is cross-referenced across 3+ independent outlets, drafted with AI assistance by the newsroom system (Drafter → Editor → Fact-Checker → Polisher), and reviewed by Serhat Er, Editor-in-Chief, before publication. We disclose AI augmentation openly. Editorial accountability stays with the named editor on every article. Tips: editorial@byte-pulse.net.

HardwareAIGamingMobileSecurity
Editorially reviewed on . Spotted an error? Tell us.
From other sections

Don’t miss these

CD Projekt Red's 2028 Witcher 4 Target: Operational Strategy Over Release Date
🎮 Gaming

CD Projekt Red's 2028 Witcher 4 Target: Operational Strategy Over Release Date

Byte-Pulse examines CD Projekt Red's 2028 target for The Witcher 4, arguing the real story is the operational strategy behind a major Witcher 3 expansion.

By Byte-Pulse Newsroom·3 days ago·7 min
Apple's AI Pivot: Vision Pro Content Cut, Siri Rebuilt Amid Layoffs
⚙️ Hardware

Apple's AI Pivot: Vision Pro Content Cut, Siri Rebuilt Amid Layoffs

Apple's latest layoffs signal a strategic pivot, dialing back high-cost Vision Pro content while re-tooling Siri for the AI era. What's next for Apple?

By Byte-Pulse Newsroom·5 days ago·8 min
Apple's 'Deep Discounts': US Inventory Flush, Not European Bargains
📱 Mobile

Apple's 'Deep Discounts': US Inventory Flush, Not European Bargains

Byte-Pulse examines Apple's recent US sales, revealing that 'deep discounts' on popular devices like the iPhone 17 Pro and M3 iPad Air are less about consumer savings and more about clearing stock ahead of new launches. We critically assess whether these offers translate to real value for European buyers.

By Byte-Pulse Newsroom·Aug 19, 2026·7 min
D23 2026: Disney's Content Deluge Sparks Questions About Strategy
🌐 Web & Apps

D23 2026: Disney's Content Deluge Sparks Questions About Strategy

Byte-Pulse cuts through D23 hype: We dissect Disney's ambitious content slate, from Simpsons: Hit & Run to Ahsoka season 2, and question the real-world implications and European market strategy.

By Byte-Pulse Newsroom·Aug 15, 2026·4 min
Zelnick's Streaming Vision: Hype or Hard Reality for GTA 6?
🎮 Gaming

Zelnick's Streaming Vision: Hype or Hard Reality for GTA 6?

Byte-Pulse examines Take-Two CEO Strauss Zelnick's bold prediction of widespread game streaming by 2029, contrasting it with the immediate demands of GTA 6 and the often-overlooked practicalities of European hardware logistics.

By Byte-Pulse Newsroom·Aug 08, 2026·7 min
Povasee A30 Jump Starter: A 50-Euro Deal With 5,000A Claims Under Scrutiny
⚙️ Hardware

Povasee A30 Jump Starter: A 50-Euro Deal With 5,000A Claims Under Scrutiny

The Povasee A30 jump-start power bank, on offer at Amazon for under 50 Euros, claims 5,000A peak current. We scrutinize this deal against real-world expectations.

By Byte-Pulse Newsroom·Aug 20, 2026·7 min
Cookies & ads

We fund this site through ads (Google AdSense and others) and use analytics to see what works. Both may set cookies. You decide what is OK — your choice is remembered.

Details in our Privacy Policy.