2026 Charter Communications / Spectrum — 4.9M accounts; ShinyHunters vishing → Salesforce (Apr; May disclosure)
Data compromised
Names, emails, addresses, phones, plan info; ~85k employee directory rows with job titles; actor-claimed CPNI/support data
Technical writeup
Charter Communications, which serves tens of millions of U.S. customers through the Spectrum brand, confirmed in late May 2026 that it suffered a data breach after ShinyHunters listed the company and later leaked Salesforce data when ransom was refused. ShinyHunters told BleepingComputer they intruded around April 1, 2026 via voice phishing that compromised an employee Microsoft Entra account and claimed roughly 40 million Salesforce rows—including names, emails, addresses, phones, plan information, some CPNI, and support tickets. Have I Been Pwned analyzed the published archive and confirmed 4.9 million accounts with names, emails, phone numbers, and physical addresses, plus roughly 85,000 internal employee-directory rows with job titles. Charter’s statement said no sensitive personal information (PI) or CPNI was exfiltrated—language that diverged from criminal marketing and independent verification. BreachHistory uses the HIBP-verified 4.9M account figure as the headline count.
Root cause
Vishing compromise of employee Microsoft Entra account enabling Salesforce data export; ShinyHunters extortion
References
- https://www.bleepingcomputer.com/news/security/charter-communications-data-breach-affects-49-million-accounts/
- https://www.bleepingcomputer.com/news/security/charter-confirms-data-breach-after-shinyhunters-extortion-threat/
- https://haveibeenpwned.com/Breach/Charter
- https://www.pkware.com/blog/2026-data-breaches