← Home

Charter Data Breach Exposes 4.9 Million Customer Accounts

Extortion gang ShinyHunters claims responsibility for April 1st vishing attack that accessed Salesforce data.

By Serhat Kalender·Editor-in-Chief·May 29, 2026·3 min read0
Charter Data Breach Exposes 4.9 Million Customer Accounts
Image source: BleepingComputer

Charter Communications, the U.S. telecom giant behind the Spectrum brand, confirmed a data breach. It exposed personal info from nearly 5 million customer accounts. The incident happened in early April. The extortion gang ShinyHunters says it was a voice phishing (vishing) attack.

The Attack Vector

ShinyHunters claims the breach started April 1st. Attackers compromised an employee's Microsoft Entra account. They used a vishing scheme. This initial access reportedly let them into Charter's Salesforce instance. Salesforce is a popular customer relationship management platform. The gang says they stole 42 million records. That’s a lot. It included names, email addresses, physical addresses, phone numbers, plan details, and some customer proprietary network information (CPNI).

Charter serves over 32 million customers across 41 U.S. states. They initially said no sensitive personal info or CPNI was taken. But the data breach service Have I Been Pwned looked at the data ShinyHunters leaked. They confirmed it impacted 4.9 million unique accounts. Exposed data included names, email addresses, phone numbers, and physical addresses. About 85,000 records, apparently from an internal employee directory, also had job titles.

The Ransom Demand and Leak

ShinyHunters demanded a ransom from Charter. They wanted the stolen data back and destroyed. Charter refused. So, the cybercrime group leaked the compromised info on their dark web site. Byte-Pulse asked Charter for comment about the difference between their initial statement and the gang's CPNI claims. We were just directed back to the company's original statement.

"No sensitive personal information (PI) or customer proprietary network information (CPNI) data was exfiltrated by the threat actor as a result of recent activity," Charter told BleepingComputer.

This incident adds to ShinyHunters' history. They've targeted Salesforce customers before. Over the past year, the group has been linked to many breaches worldwide. They claim to have stolen billions of records using similar attacks.

Context and Impact

This breach shows the ongoing threat from sophisticated social engineering attacks. Even big telecom companies aren't immune. The FBI recently advised victims of ShinyHunters not to pay ransom demands. They say payment doesn't guarantee data deletion. It might even lead to more extortion or sales to other criminals.

Charter Communications is a big player in the U.S. telecom market. They provide internet, mobile, video, and voice services. A breach this size can still impact customers. Even if Charter says sensitive data wasn't compromised. Identity theft, targeted phishing, and spam all increase when personal contact info is leaked.

The FBI recently advised ShinyHunters' victims not to give in to the gang's ransom demands. They'd previously warned that doing so can't guarantee threat actors won't try to sell the stolen data to other cybercriminals or extort them again.

What's Still Unclear:

  • Did CPNI data get exfiltrated? Have I Been Pwned confirmed contact details for 4.9 million accounts were exposed. But confirmation on whether any CPNI data was actually stolen is still missing. Charter sticks to its original stance.
  • How exactly did the vishing work? The specific details of the vishing attack and how the employee's Microsoft Entra account was compromised aren't public.
  • What's the full scope of Salesforce data? ShinyHunters claimed 42 million records. But the complete inventory of data within the compromised Salesforce instance isn't detailed.

Why This Matters:

Charter's data breach highlights the critical need for strong cybersecurity. Defenses must counter evolving social engineering tactics. The incident serves as a stark reminder. Even with solid technical safeguards, human vulnerability is a primary attack vector. It can expose millions of customers to more risks.

#charter#data breach#shinyhunters#salesforce#vishing#cybersecurity
Get the 5 tech stories worth your time — 3× a week

One short email. The most important Security news, fact-checked, no fluff. Free, unsubscribe anytime.

More from Security

From other sections

Don’t miss these

🎮 Gaming

Honkai: Star Rail 4.3 Drops Early: What You Need to Know

Honkai: Star Rail version 4.3 is rolling out on an unusual Sunday/Monday schedule, bringing the new Blade Mortenax character and fresh mini-games. Here's when maintenance begins and ends in your time zone.

By Byte-Pulse Newsroom·1 min ago·1 min0
🔬 Science

Star City Explores the Human Cost Behind the Soviet Space Program

Forget Mars colonies. Star City, the new spin-off from For All Mankind, dives deep into the gritty, dangerous, and often ethically complex world of the Soviet space program in the late 1960s.

By Serhat Kalender·2h ago·1 min0
⚙️ Hardware

M5 MacBook Air and iPad Deals: Up to $270 Off and $299 Base iPad

Score Apple's M5 MacBook Air for up to $270 off, base iPads at $299, and Apple Watch Solo Loops starting at $9 in a wave of new deals.

By Byte-Pulse Newsroom·13h ago·1 min0
📱 Mobile

Samsung Galaxy Watch Ultra 2: Two Models Coming in 2026 with LTE and Wi-Fi-Only Options

Samsung's upcoming Galaxy Watch Ultra 2, expected in July 2026, might arrive in two distinct versions: one with LTE and another purely Wi-Fi/Bluetooth. This move is reportedly driven by rising production costs and aims to offer a more accessible entry point.

By Byte-Pulse Newsroom·14h ago·1 min0
🤖 AI

Anthropic's Claude Opus 4.8 Advances AI Honesty, 'Mythos' Model Nears

Anthropic rolls out Claude Opus 4.8, highlighting its enhanced honesty and decision-making capabilities. A next-gen 'Mythos' model is also slated for release soon, promising even greater intelligence.

By Serhat Kalender·18h ago·1 min0

Jackass 5 Wraps Franchise with Nostalgia and Robotics

The Jackass series concludes with its fifth film, featuring nostalgia-filled clips and a new robotic cast member, releasing June 2026.

By Byte-Pulse Newsroom·6 days ago·1 min0