Charter confirms data breach after ShinyHunters extortion threat

Charter confirms data breach after ShinyHunters extortion threat

Charter confirms data breach after ShinyHunters extortion threat

https://www.bleepingcomputer.com/news/security/charter-confirms-data-breach-after-shinyhunters-extortion-threat/

Publish Date: 2026-05-26 15:46:01

Source Domain: www.bleepingcomputer.com

Data Breach at Charter Communications

U.S. telecommunications giant Charter Communications experienced a significant data breach confirmed by the infamous hacking group ShinyHunters. The attack saw the group threatening to release stolen data unless a ransom is paid. Charter, operating under the Spectrum brand, serves millions of residential and business customers. In response, the company affirmed it is following its security protocols, cooperating with authorities, and reassured customers that no sensitive personal or customer proprietary network data was compromised. However, ShinyHunters claimed to have stolen 40 million records consisting of personal information like names, email addresses, phone numbers, and some customer proprietary network information. The attackers breached an employee’s account via voice phishing, enabling them to access Salesforce data. Since last year, the criminal group has intensified its social engineering campaigns, targeting various single sign-on accounts to access multiple SaaS applications and leveraging them to extort companies by threatening data leaks.

Key Points:

  • Charter Communications confirmed a data breach by the ShinyHunters group without leakage of sensitive customer data.
  • The stolen data includes personal information, phone numbers, and some customer proprietary network data.
  • The breach occurred via voice phishing, compromising an employee’s account to access Salesforce.
  • ShinyHunters has been known for wide-ranging social engineering campaigns and extortion through stolen data targeting various SaaS applications.
  • Charter is cooperating with authorities, following security protocols, and ensuring no customer proprietary network information was breached.