Charter Communications—which markets internet, TV, mobile, and voice service to tens of millions of U.S. households under the Spectrum brand—confirmed a late-May 2026 data breach after the ShinyHunters extortion gang published data stolen from its environment. Independent verification by Have I Been Pwned pegs the consumer impact at 4.9 million accounts, a figure materially lower than the gang’s 40-million-row Salesforce marketing but still large enough to fuel credential-stuffing, SIM-swap, and targeted phishing at national scale.
Attack path: vishing, Entra, and Salesforce
ShinyHunters told BleepingComputer they compromised Charter around April 1, 2026 via voice phishing (vishing) against an employee, obtaining access to a Microsoft Entra identity and exporting millions of rows from Salesforce. Claimed fields included consumer and business customer names, emails, physical addresses, phone numbers, plan information, support-ticket content, and some customer proprietary network information (CPNI). After Charter refused ransom, the group leaked archives on its dark-web site.
What Charter says vs. what researchers verified
Charter’s public statement said no sensitive personal information (PI) or CPNI was exfiltrated—language that conflicts with ShinyHunters’ marketing and with downstream analysis. Have I Been Pwned confirmed 4.9 million unique email addresses with names, phone numbers, and physical addresses in the published dump, plus approximately 85,000 internal employee-directory records including job titles. BreachHistory uses the HIBP-verified account count as the headline metric because it is independently reproducible.
Why telecom breaches hurt more than “just contact info”
Spectrum credentials gate billing portals, Wi-Fi provisioning apps, and sometimes carrier-controlled email mailboxes. Combined with phone numbers and addresses, attackers can:
- Attempt SIM swaps or number-porting fraud to intercept SMS two-factor codes
- Run convincing support scams citing real plan details or ticket subjects
- Stuff passwords against banks and retailers where customers reused Spectrum passwords
FBI guidance on paying extortionists
The FBI has advised ShinyHunters victims not to pay ransoms, noting payment does not guarantee deletion and may invite re-extortion. Charter’s refusal to pay aligns with that guidance but increases the likelihood of continued circulation of leaked rows in criminal ecosystems—treat the data as permanently untrustworthy.
Steps for Spectrum customers
- Change Spectrum account passwords and enable MFA where available.
- Call your mobile carrier to add a port-out PIN or transfer lock.
- Review bank and credit-card alerts; enable transaction notifications.
- Be skeptical of “Spectrum security department” outbound calls—hang up and dial official support from your bill.
Context: Salesforce targeting in 2026
Charter sits in a long line of Salesforce-linked ShinyHunters victims documented throughout 2025–2026, including Aura and Salesloft Drift campaigns affecting hundreds of organizations. Security teams should audit OAuth integrations, session policies, and help-desk verification procedures—not only perimeter firewalls.
Business vs. residential customers
Charter serves both households and small businesses; leaked support tickets may include circuit IDs, billing disputes, and internal escalation notes useful for BEC attacks against IT admins. Business customers should rotate VPN and portal credentials tied to Spectrum accounts and review whether static IPs or service addresses appear in leaked rows.
CPNI and FCC context
Telecom breaches implicate Customer Proprietary Network Information rules when call-detail or service metadata is exposed. Charter’s denial of CPNI exfiltration is legally significant but does not eliminate risk from exposed emails, addresses, and employee directories—categories HIBP already confirmed at scale.
Have I Been Pwned and consumer verification
Email users can check exposure via HIBP’s Charter entry, but absence of a hit does not guarantee safety—household accounts may be affected under different emails or business service IDs. Encourage family members who share Spectrum bundles to verify each email alias.
Salt Typhoon and nation-state context (separate incident class)
Reporting in 2024–2025 documented separate nation-state intrusions into U.S. telecom backends (often discussed under “Salt Typhoon”). The May 2026 ShinyHunters Salesforce leak is a distinct criminal extortion path—consumers should not conflate the two, but enterprise teams must prioritize both help-desk integrity and lawful intercept architecture reviews.
Further resources
Read our ShinyHunters May 2026 overview, track updates on the Charter timeline, and explore BreachHistory platform tools for multi-company research. Browse more analysis on the breach blog.
Canonical record: Charter 2026 breach.
What Spectrum will not fix for you
Charter cannot rotate your non-Spectrum passwords or remove your email from criminal forums after a leak. Treat this breach as a personal infosec reset: adopt a password manager, use unique emails for financial accounts, and enable phishing-resistant MFA on email.
Employee directory exposure
The roughly 85,000 employee-directory rows HIBP identified enable spear-phishing against Charter staff and partners. If you are an employee, report suspicious internal HR or IT tickets to corporate security rather than clicking OAuth consent prompts.
Bundled services
Households with Spectrum TV, internet, and mobile on one bill should assume multiple account identifiers could map to the same family—update security questions on each product portal.
Sources: BleepingComputer, Have I Been Pwned