Last updated 1 month ago
Charter Communications, the parent company of the Spectrum consumer broadband and cable brand, experienced a data breach in May 2026. The ShinyHunters group conducted a 'pay or leak' extortion campaign, later publishing the stolen data. The breach exposed 4,851,517 unique email addresses along with names, phone numbers, and physical addresses. A subset of approximately 85,000 records from an internal employee directory also included job titles.
The attack vector was unauthorized access, with the ShinyHunters group exfiltrating data from Charter's systems. The group is known for extortion-driven breaches and data sales. The compromised data types include email addresses, names, phone numbers, physical addresses, and job titles for a subset of records. Charter confirmed the incident but stated that no sensitive personal information or customer proprietary network information (CPNI) was exfiltrated.
Charter confirmed the breach publicly in May 2026. No further post-incident details such as regulatory actions, litigation, or ransom payments were disclosed in the article.
Data exfiltrated by ShinyHunters group and published after extortion campaign
Charter Communications, a major telecommunications provider, failed to prevent unauthorized access by the ShinyHunters group, leading to the exfiltration of 4.9 million customer records including email addresses, names, phone numbers, and physical addresses. This incident highlights the need for robust access controls and monitoring to detect and block unauthorized data access, particularly for customer-facing systems. The inclusion of job titles from an internal employee directory suggests inadequate segmentation between customer and employee data stores, which should have been isolated to limit exposure.
Sign in to join the discussion.
Company
Industry
Location
Disclosed
Records Affected
Attack Vector
Threat Actor
Continent
Country
Industry
Attack Vector
Threat Actor