Charter Communications
Incident posture
Linked entities
- Victim
- Charter Communications
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
Charter Communications suffered a cyberattack in which an extortion group stole over 42 million customer records and posted them on a leak site, affecting nearly five million individuals. The exposed information included email addresses, names, addresses, phone numbers, and employee data, and the publication on the leak site allowed unauthorized access to these details.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
In May 2026, Charter Communications was affected by a cyberattack attributed in the account to an extortion group. The group stole data from the company and published the stolen material on a leak site. The incident involved more than 42 million customer records, making it one of the large-scale data breaches described for 2026. The account stated that almost five million people were affected by the breach. The exposed information included email addresses, names, physical addresses, and phone numbers. Employee information was also included among the stolen data.
The incident centered on the theft and public release of records rather than on a described disruption to Charter Communications’ services. The account did not identify the extortion group by name. It also did not describe the method used to access Charter’s systems, the date the intrusion began, or the systems involved. The confirmed sequence in the account was that data was stolen in May 2026 and then published on a leak site. The publication of the records created a documented exposure of customer and employee information.
The impact described in the account involved both scale and sensitivity of the exposed data. More than 42 million records were reported stolen, while nearly five million people were described as affected. The exposed customer data included common identifiers and contact details, including names, addresses, phone numbers, and email addresses. Employee information was also compromised, extending the incident beyond customer records alone. Because the stolen data was published on a leak site, the information was no longer limited to the extortion group’s possession according to the account.
No containment action, remediation step, customer notification process, law-enforcement action, or regulatory response was described in the provided account. No further detail was given about whether Charter Communications confirmed the full scope beyond the reported publication, whether the leak site remained active, or whether additional records were released after the initial posting. The incident was presented as a 2026 data breach involving Charter Communications, an extortion group, stolen customer and employee information, and public publication of the data.
Sources
Sources available to members: 1 source.