Cyber Incident Victim: Time Warner Cable
Date:
Jan 2016
Location:
United States of America
Summary
Approximately 320,000 customer accounts were compromised through unauthorized access to email addresses and passwords used for the cable provider's service portal. The incident was identified after the FBI alerted the company to a cache of stolen credentials, though no payment card or additional personal information was confirmed exposed. While the breach did not originate from direct infiltration of the provider's systems, potential sources included phishing campaigns targeting customers, malware infections, or compromise of a third-party contractor with account access. Affected customers received notifications urging password resets, and broader credential reuse risks were highlighted given similar recent incidents impacting other major providers.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 3 motives | 3 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
In January 2016, Time Warner Cable (TWC) confirmed that approximately 320,000 customer accounts were compromised after the FBI alerted the company to a cache of stolen credentials. The exposed data included customer email addresses and passwords used to access TWC’s customer service portal, but no payment card details or other personal information. TWC initiated notifications to affected customers, urging them to reset their passwords and monitor bank statements for suspicious activity. Investigators found no evidence of a direct breach of TWC’s internal systems, suggesting the credentials were obtained externally. The FBI’s involvement in identifying the leak indicated third-party criminal activity rather than an intrusion into TWC’s infrastructure. While the exact method of credential collection remained unconfirmed, phishing campaigns, malware infections, or a breach of a TWC subcontractor were considered plausible sources. The scale of the theft—representing roughly 2% of TWC’s 16 million customers—highlighted the potential effectiveness of sustained credential-harvesting operations over time.

TWC’s public response emphasized password resets for impacted accounts and advised against password reuse across multiple services, noting criminals often test stolen credentials on other platforms. The company did not disclose technical specifics about the credential validation process or any internal security audits conducted following the incident. Concurrently, reports surfaced of a separate leak involving 200,000 Comcast customer credentials, underscoring broader industry vulnerabilities. TWC’s communications framed the incident as externally sourced, avoiding acknowledgments of internal security failures. No further details were provided regarding law enforcement investigations into the credential cache’s origins or the identity of the perpetrators. The incident remained confined to account access compromises without escalation to financial data theft or system disruptions.
