CSIDB logo
Incident

Charter Communications

Incident posture

Attack window
May 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-23 22:02

Linked entities

Victim
Charter Communications
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
May 2026
Discovered
Undetermined
Disclosed
May 2026
Resolved
Pending

Summary

Charter Communications suffered a cyberattack in which an extortion group stole over 42 million customer records and posted them on a leak site, affecting nearly five million individuals. The exposed information included email addresses, names, addresses, phone numbers, and employee data, and the publication on the leak site allowed unauthorized access to these details.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

0 techniques

Description

In May 2026, Charter Communications was affected by a cyberattack attributed in the account to an extortion group. The group stole data from the company and published the stolen material on a leak site. The incident involved more than 42 million customer records, making it one of the large-scale data breaches described for 2026. The account stated that almost five million people were affected by the breach. The exposed information included email addresses, names, physical addresses, and phone numbers. Employee information was also included among the stolen data.

The incident centered on the theft and public release of records rather than on a described disruption to Charter Communications’ services. The account did not identify the extortion group by name. It also did not describe the method used to access Charter’s systems, the date the intrusion began, or the systems involved. The confirmed sequence in the account was that data was stolen in May 2026 and then published on a leak site. The publication of the records created a documented exposure of customer and employee information.

The impact described in the account involved both scale and sensitivity of the exposed data. More than 42 million records were reported stolen, while nearly five million people were described as affected. The exposed customer data included common identifiers and contact details, including names, addresses, phone numbers, and email addresses. Employee information was also compromised, extending the incident beyond customer records alone. Because the stolen data was published on a leak site, the information was no longer limited to the extortion group’s possession according to the account.

No containment action, remediation step, customer notification process, law-enforcement action, or regulatory response was described in the provided account. No further detail was given about whether Charter Communications confirmed the full scope beyond the reported publication, whether the leak site remained active, or whether additional records were released after the initial posting. The incident was presented as a 2026 data breach involving Charter Communications, an extortion group, stolen customer and employee information, and public publication of the data.

Sources

Sources available to members: 1 source.

CSIDB