Charter Communications
Incident posture
Linked entities
- Victim
- Charter Communications
- Threat actors
- 1 actor
- Sources
- 3 sources
Timeline
Summary
Charter Communications confirmed a Spectrum‑linked data breach after the ransomware group ShinyHunters claimed to have accessed its systems via a vishing attack that compromised an employee’s Microsoft Entra account and reached Salesforce data. The company stated that no sensitive personal information or CPNI was exfiltrated, though breach monitoring linked the incident to approximately 4.9 million accounts with names, email addresses, phone numbers, physical addresses and job titles exposed. ShinyHunters asserted that they stole millions of records, including names, email addresses, addresses, phone numbers, phone types, plan information, support ticket data and some CPNI, prompting lawsuits alleging over 42 million records were compromised.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
Charter Communications confirmed a Spectrum‑linked data breach on May 26 2026 after the ransomware group ShinyHunters threatened to leak stolen data. According to ShinyHunters, the intrusion began on April 1 2026 when a voice phishing (vishing) call compromised an employee’s Microsoft Entra account, which then provided access to Charter’s Salesforce instance. The group claimed it exported millions of consumer and business customer records, including names, email addresses, home addresses, phone numbers, phone type, plan information, support ticket data and some CPNI data. Charter stated that its investigation found no sensitive personal information or CPNI was exfiltrated and that only the sales tools used to manage current, past and prospective business customers were impacted; breach monitoring later tied the exposed dataset to 4.9 million accounts. At the time of the incident Charter reported approximately 31.7 million customers and had announced in May 2025 an agreement to merge with Atlanta‑based Cox Communications, with the combined entity to be headquartered at Charter’s Stamford location.
In response to the breach Charter said it was following its security protocols and working with appropriate authorities. The disclosure prompted at least four class‑action lawsuits filed in federal court in Connecticut, with plaintiffs from New York, Texas and North Charter. The lawsuits allege that Charter’s inadequate data security allowed hackers to access personally identifiable information, post it on the dark web and expose plaintiffs to heightened risk of fraud, identity theft, misappropriation of financial benefits and privacy intrusion. One lawsuit cites a Bleeping Computer article containing a screenshot purportedly from ShinyHunters that states “Over 42M records containing PII have been compromised” and includes a “final warning” to pay or leak the data. The plaintiffs seek unspecified damages and contend that, as a result of the breach, they must monitor Social Security and other benefits, frequently change login credentials, scrutinize communications for social engineering attempts and pursue identity theft protection and credit monitoring services. Charter has maintained that no CPNI or sensitive personal information was released and that the incident was limited to its business‑customer sales tools. The breach remains subject to ongoing litigation and regulatory scrutiny.
Sources
Sources available to members: 3 sources.