
Charter Communications Confirms Data Breach After ShinyHunters Extortion Threat
U.S. telecommunications giant Charter Communications (operating as Spectrum) confirmed a data breach after the ShinyHunters extortion group threatened to leak stolen data. The breach, which reportedly occurred on April 1, 2026, involved a vishing attack that compromised an employee's Microsoft Entra account, leading to the export of millions of customer records from the company's Salesforce instance. ShinyHunters claimed to have stolen 40 million (or 4.9 million to 13 million in other reports) customer records, including names, email addresses, physical addresses, phone numbers, plan information, and customer support ticket data. Charter denied that sensitive personal information or customer proprietary network information (CPNI) was exfiltrated.
Signal context
First seen: May 26, 2026
Last updated: Jun 24, 2026
Status: Public signal
Key points
- Charter Communications confirmed a data breach following extortion threats from ShinyHunters.
- ShinyHunters claimed to have stolen 40 million records, though other reports indicate 4.9 million to 13 million.
- Exposed data includes names, email addresses, physical addresses, phone numbers, plan information, and customer support ticket data.
Signal analysis
BetaThis analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.
Sector: Information
Likely country: Location not provided
The feed marks multiple actor roles. Treat this as a review signal rather than a final attribution.
- Source type: outside the affected organization
- Source type: possible insider or internal misuse
Impact area: Confidentiality
Likely asset: User or customer data
- 19 signals in the same sector
- 66 signals with the same likely impact area
- 1 signal linked to this organization/domain
External sources
Charter confirms data breach after ShinyHunters extortion threat - Bleeping Computerhttps://www.bleepingcomputer.com/news/security/charter-confirms-data-breach-after-shinyhunters-extortion-threat/Public source from bleepingcomputer.com.
ShinyHunters extorts Charter Communications after data breach | brief | SC Mediahttps://www.scmagazine.com/brief/shinyhunters-extorts-charter-communications-after-data-breachPublic source from scmagazine.com.
Related signals
Grouped by why the signal is relevant.
Dutch civil servants from Authority for Consumers and Markets (ACM) affected by Microsoft data leak
Names of civil servants from the Authority for Consumers and Markets (ACM), involved in implementing the Digital Services Act (DSA), were reportedly shared by Microsoft with the U.S. House of Representatives without redaction.
LastPass confirms data breach in Klue supply chain attack
LastPass announced that hackers accessed customer data from its Salesforce environment after stealing the company's OAuth tokens in a supply chain attack targeting Klue, a third-party market intelligence platform. The unauthorized actor obtained OAuth tokens from Klue, which were then used to access LastPass customer data. Exposed information includes customer names, phone numbers, email addresses, physical addresses, support case information, and sales/CRM-related data. LastPass stated that its core products, services, and infrastructure, including customer vaults, were not affected by this incident. The Icarus extortion group claimed responsibility for the Klue attack.
Snyk impacted by Klue supply chain attack
Snyk, a cybersecurity firm, was affected by a supply chain attack on market intelligence platform Klue. The attack compromised Klue's integration with Salesforce, leading to the exfiltration of business information from Snyk's Salesforce CRM, including sales account data and business contact information such as names, email addresses, job titles, and phone numbers. Snyk stated the intrusion was limited to its Salesforce instance and did not involve its internal systems.
OneTrust impacted by Klue supply chain attack
OneTrust, a cybersecurity firm, was affected by a supply chain attack on market intelligence platform Klue. The attack compromised Klue's integration with Salesforce, leading to the exfiltration of business information from OneTrust's Salesforce CRM, including sales account data and business contact information such as names, email addresses, job titles, and phone numbers. OneTrust stated the intrusion was limited to its Salesforce instance and did not involve its internal systems.
Jamf impacted by Klue supply chain attack
Jamf, a cybersecurity firm, was affected by a supply chain attack on market intelligence platform Klue. The attack compromised Klue's integration with Salesforce, leading to the exfiltration of business information from Jamf's Salesforce CRM, including sales account data and business contact information such as names, email addresses, job titles, and phone numbers. Jamf stated the intrusion was limited to its Salesforce instance and did not involve its internal systems.
Huntress impacted by Klue supply chain attack
Huntress, a cybersecurity firm, was affected by a supply chain attack on market intelligence platform Klue. The attack compromised Klue's integration with Salesforce, leading to the exfiltration of business information from Huntress's Salesforce CRM, including sales account data and business contact information such as names, email addresses, job titles, and phone numbers. Huntress suggested that a threat actor named Icarus might have been responsible for the attack.
