CSIDB logo
Incident

Charter Communications

Incident posture

Attack window
Apr 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-08-26 23:54

Linked entities

Victim
Charter Communications
Threat actors
1 actor
Sources
3 sources

Timeline

Occurred
Apr 2026
Discovered
Undetermined
Disclosed
May 2026
Resolved
Pending

Summary

Charter Communications confirmed a Spectrum‑linked data breach after the ransomware group ShinyHunters claimed to have accessed its systems via a vishing attack that compromised an employee’s Microsoft Entra account and reached Salesforce data. The company stated that no sensitive personal information or CPNI was exfiltrated, though breach monitoring linked the incident to approximately 4.9 million accounts with names, email addresses, phone numbers, physical addresses and job titles exposed. ShinyHunters asserted that they stole millions of records, including names, email addresses, addresses, phone numbers, phone types, plan information, support ticket data and some CPNI, prompting lawsuits alleging over 42 million records were compromised.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

Charter Communications confirmed a Spectrum‑linked data breach on May 26 2026 after the ransomware group ShinyHunters threatened to leak stolen data. According to ShinyHunters, the intrusion began on April 1 2026 when a voice phishing (vishing) call compromised an employee’s Microsoft Entra account, which then provided access to Charter’s Salesforce instance. The group claimed it exported millions of consumer and business customer records, including names, email addresses, home addresses, phone numbers, phone type, plan information, support ticket data and some CPNI data. Charter stated that its investigation found no sensitive personal information or CPNI was exfiltrated and that only the sales tools used to manage current, past and prospective business customers were impacted; breach monitoring later tied the exposed dataset to 4.9 million accounts. At the time of the incident Charter reported approximately 31.7 million customers and had announced in May 2025 an agreement to merge with Atlanta‑based Cox Communications, with the combined entity to be headquartered at Charter’s Stamford location.

In response to the breach Charter said it was following its security protocols and working with appropriate authorities. The disclosure prompted at least four class‑action lawsuits filed in federal court in Connecticut, with plaintiffs from New York, Texas and North Charter. The lawsuits allege that Charter’s inadequate data security allowed hackers to access personally identifiable information, post it on the dark web and expose plaintiffs to heightened risk of fraud, identity theft, misappropriation of financial benefits and privacy intrusion. One lawsuit cites a Bleeping Computer article containing a screenshot purportedly from ShinyHunters that states “Over 42M records containing PII have been compromised” and includes a “final warning” to pay or leak the data. The plaintiffs seek unspecified damages and contend that, as a result of the breach, they must monitor Social Security and other benefits, frequently change login credentials, scrutinize communications for social engineering attempts and pursue identity theft protection and credit monitoring services. Charter has maintained that no CPNI or sensitive personal information was released and that the incident was limited to its business‑customer sales tools. The breach remains subject to ongoing litigation and regulatory scrutiny.

Sources

Sources available to members: 3 sources.

CSIDB