Cyber Incident Victim: Charter Communications
Timeline
Summary
Charter Communications confirmed a Spectrum‑linked data breach after a threat actor claimed to have stolen data through a vishing attack that compromised an employee Microsoft Entra account and accessed Salesforce data. The company said no sensitive personal information or CPNI was exfiltrated but later monitoring linked the exposed dataset to about 4.9 million accounts containing names, email addresses, phone numbers, physical addresses, and job titles. The actor threatened to leak the stolen information unless demands were met.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
On 1 April 2026 ShinyHunters claimed to have breached Charter Communications through a vishing attack that compromised an employee’s Microsoft Entra account, which subsequently granted access to Salesforce data. The threat actor asserted that the intrusion occurred around that date. On 26 May 2026 Charter Communications confirmed a Spectrum‑linked data breach after ShinyHunters threatened to leak the stolen information. Charter stated that the breach was confirmed following the threat and that it had launched an investigation. The company said that no sensitive personal information or customer proprietary network information (CPNI) was exfiltrated during the incident.

Although Charter maintained that no sensitive data was taken, subsequent breach monitoring linked the exposed dataset to approximately 4.9 million customer accounts. The information that was accessed included names, email addresses, telephone numbers, physical addresses, and job titles. Charter emphasized that the compromised data did not contain social security numbers, financial details, or other protected CPNI. The exposure of names and contact details nevertheless represents a privacy concern for the affected accounts. The company noted that the breach was limited to the Salesforce data accessed via the compromised employee account.
In response to the disclosure, Charter issued a public statement confirming the breach and reiterating that no sensitive personal information or CPNI had been taken. The company said it had revoked the compromised credentials, reissued keys, deployed fixes, and added monitoring to detect further unauthorized activity. Charter also indicated that it was working with law‑enforcement and forensic investigators to assess the scope of the incident. The firm stated that it would continue to monitor for any misuse of the exposed data. No evidence of password, birth date, government identifier, or financial data theft was found.
Charter is one of the United States’ largest telecommunications providers, serving roughly 31.7 million customers as of the end of March 2026. In May 2025 the company announced an agreement to merge with Atlanta‑based Cox Communications, with the combined entity to be headquartered at Charter’s current headquarters, 400 Washington Boulevard in downtown Stamford, where about 1,800 Charter employees are based. Charter CEO Chris Winfrey is slated to assume the same role at the newly formed company, which will be called Cox Communications. The merger was announced prior to the Spectrum breach and remains part of Charter’s ongoing corporate strategy. The breach disclosure in May 2026 occurred while the merger plans were still being finalized.
