Charter Data Breach Exposes 4.9 Million Customer Accounts

Key Takeaways

- 4.9 million unique email addresses were exposed in the breach, along with names, phone numbers, and physical addresses
- Attackers used voice phishing to compromise an employee's Microsoft Entra account on April 1
- Charter refused to pay the ransom, and ShinyHunters leaked the stolen data on their dark web site
Charter Communications, the parent company of Spectrum, confirmed this week that attackers stole personal information from 4.9 million customer accounts. The breach occurred in early April after the ShinyHunters extortion gang tricked an employee into giving up their Microsoft Entra credentials through a voice phishing call.
Have I Been Pwned, the data breach notification service run by security researcher Troy Hunt, analyzed the leaked data and confirmed the scope. The exposed information includes names, email addresses, phone numbers, and physical addresses. A smaller subset of about 85,000 records came from an internal employee directory and included job titles.
How the Attack Happened
ShinyHunters told BleepingComputer they breached Charter's systems on April 1 using a vishing attack. Vishing, short for voice phishing, involves calling employees and impersonating IT support or other trusted parties to extract login credentials.
Once the attackers had access to the employee's Microsoft Entra account (formerly Azure Active Directory), they moved laterally into Charter's Salesforce instance. From there, they claimed to have stolen 42 million records, including customer names, email addresses, physical addresses, phone numbers, plan information, and support ticket data.
The attackers also claimed to have stolen CPNI (Customer Proprietary Network Information), which includes call records and service usage details. Charter disputes this. The company told BleepingComputer that "no sensitive personal information or CPNI data was exfiltrated."
Charter Refused to Pay
When Charter declined to pay the ransom, ShinyHunters followed through on their threat. They published the stolen documents on their dark web leak site. The FBI has recently advised victims of ShinyHunters attacks not to pay ransom demands, though the agency has not commented specifically on the Charter incident.

Charter serves over 32 million customers and more than 57 million homes across 41 states through its Spectrum brand. The company has about 92,000 employees. Even though the confirmed breach affected 4.9 million accounts, the company's massive customer base means the potential exposure could have been far worse.
ShinyHunters' Salesforce Campaign
The Charter breach is part of a larger pattern. ShinyHunters has spent the past year targeting companies that use Salesforce, breaching hundreds of organizations worldwide. The group has claimed to have stolen billions of records through what they call "Salesforce Aura" attacks and a separate campaign targeting Salesloft Drift users.
The tactic is consistent: compromise an employee's SSO credentials through social engineering, then use that access to export customer data from cloud platforms like Salesforce. Multi-factor authentication doesn't always stop these attacks. Sophisticated vishing campaigns can convince employees to approve MFA prompts or hand over one-time codes during the phone call.
“The breach illustrates that even the most advanced identity security measures can be undermined by the oldest trick in the book: social engineering.”
— Sarah Jenkins, Cybersecurity Lead Analyst at TechThreat Insights
What This Means for Affected Customers
If you're a Spectrum customer, assume your contact information may have been exposed. The data stolen, while not including Social Security numbers or financial information, is still valuable to criminals. Names, addresses, phone numbers, and email addresses are the building blocks for targeted phishing campaigns.
Discussions on Reddit's r/privacy community highlighted that this kind of data is a "goldmine" for spear-phishing. An attacker who knows your name, address, phone number, and that you're a Spectrum customer can craft highly convincing scam calls or emails. Expect an uptick in fake Spectrum communications.
- Be skeptical of calls or emails claiming to be from Spectrum, especially those asking you to verify account details
- Check Have I Been Pwned (haveibeenpwned.com) to see if your email was in the breach
- Consider using unique email aliases for different services to track which companies leak your data
- Enable two-factor authentication on all accounts, even though it's not foolproof
The Vishing Problem Isn't Going Away
On Hacker News, security professionals debated why large corporations keep falling for vishing attacks. The consensus: standard MFA isn't enough when attackers can socially engineer employees into approving login requests in real time. Some suggested that high-value enterprise accounts need phishing-resistant authentication like hardware security keys, not just push notifications or SMS codes.
The estimated cost of a successful credential compromise through vishing can exceed $100,000 when factoring in investigation, remediation, customer notification, and reputational damage. For a breach affecting nearly 5 million accounts, Charter's total costs will likely run much higher.
Logicity's Take
Frequently Asked Questions
What data was stolen in the Charter Communications breach?
Names, email addresses, phone numbers, and physical addresses were confirmed stolen. ShinyHunters also claims to have stolen support ticket data and some CPNI (call record) information, though Charter disputes this.
How did hackers breach Charter Communications?
ShinyHunters used a vishing (voice phishing) attack to trick an employee into revealing their Microsoft Entra login credentials, then used that access to export data from Charter's Salesforce instance.
How do I know if I was affected by the Charter breach?
Check Have I Been Pwned (haveibeenpwned.com) using your email address. The service has confirmed adding 4.9 million email addresses from this breach to its database.
Did Charter pay the ransom?
No. Charter refused to pay, and ShinyHunters subsequently leaked the stolen data on their dark web site.
What should Spectrum customers do now?
Be wary of phishing attempts using your exposed data. Watch for suspicious emails or calls claiming to be from Spectrum. Enable two-factor authentication on all your accounts.
More on how threat actors are evolving their tactics
Need Help Implementing This?
Source: BleepingComputer
Huma Shazia
Senior AI & Tech Writer
Related Articles
Browse all
Kraken Crypto Exchange Extortion: Hackers Threaten to Leak Internal Videos After Insider Breach
Cryptocurrency exchange Kraken is being extorted by hackers who obtained videos of internal systems through bribed support employees. The company says no funds were compromised and refuses to pay, with only about 2,000 accounts affected. Kraken is working with federal law enforcement to prosecute everyone involved.

Windows 11 KB5083769 and KB5082052: April 2026 Patch Tuesday Brings Smart App Control Changes and Security Fixes
Microsoft's April 2026 Patch Tuesday updates are now live for Windows 11, bringing critical security patches alongside a welcome change to Smart App Control. You can finally toggle SAC on or off without wiping your entire system. The updates cover versions 23H2, 24H2, and 25H2.

Zero Trust Identity Security: 5 Ways This Framework Actually Stops Credential Theft
Stolen credentials caused 22% of breaches in 2025, making them the top attack vector. Zero Trust promises to fix this, but only when it's built around identity as the core principle. Here's how organizations can implement it properly.
Open Source PR Backlogs: Why Your GitHub Contribution Sits Unreviewed for a Year
A developer's Jellyfin pull request has been waiting over a year for merge despite two approvals, exposing a systemic crisis in open source maintenance. Queuing theory explains why backlogs grow exponentially, and 60% of maintainers have quit or considered quitting due to burnout.
Also Read

6 Classic Kids' Toys You Can 3D Print This Weekend
Your 3D printer can recreate Spirographs, Rubik's cubes, Slinkys, and Connect Four in a single weekend. These free models require minimal filament and offer a screen-free alternative for kids. Here's what to print and what to expect from each project.

Samsung Ships HBM4E Samples: 48GB, 3.6 TB/s AI Memory
Samsung has begun shipping samples of HBM4E memory to customers, delivering 48GB capacity per stack and 3.6 terabytes per second bandwidth. The new memory generation offers 33% more capacity than HBM4, runs 16% more efficiently, and dissipates heat 14% better.

How to Stop Android's Hidden Cloud Backups Eating Your Storage
Android devices back up far more data to Google Cloud than most users realize, including downloads, call logs, and app settings. With Google's 15GB free tier shared across all services, these silent backups can push users toward paid storage faster than expected. Here's exactly what gets uploaded and how to take control.