Find notable cyber news and cases, enriched with sources, timelines, and signals.
Data Leak Incident

Charter customer data leak after vishing-led Salesforce access

Updated 29.05.2026 11:29
Case score 76
Case score 76 Members 2 Latest activity 29.05.2026 11:29
Members 2 First seen 26.05.2026 22:46 Last seen 29.05.2026 11:29 Updated 29.05.2026 11:29

Overview

**Charter Communications** customer data was leaked after attackers used **vishing** to compromise an employee's **Microsoft Entra** account and reach the company's **Salesforce** environment. The exposed set is confirmed at **4.9 million accounts**, and the published data includes names, email addresses, phone numbers, physical addresses, and a smaller employee-directory subset with job titles. Available material ties the intrusion and leak to **ShinyHunters** and says publication followed rejected ransom demands. Charter is alerting authorities and disputes parts of the theft narrative, so the public leak is confirmed while the full exfiltration scope remains contested.

Signals

10 derived
Impact signals
Affected 42 million records claimed Affected 4.9 million accounts Affected 40 million records (claimed)
Affected impact
Affected 4.9 million accounts Exposed data
Victims/regions
Victim region United States
Remediation
Patch No Patch
Status
Incident status Disclosed
Threat context
Actor Shinyhunters
Data exposure
Leak status Fully Leaked Data Email Addresses Data Phone Numbers Data physical addresses

Member happenings

2 related
Data Leak Charter Communications Salesforce data leak exposes 4.9 million accounts
Updated 29.05.2026 11:29 Lead Contribution 72
Data Type Email Addresses Data Type Phone Numbers Data Status Fully Leaked Patch No Patch

The **public leak** of **Charter Communications** data exposed **4.9 million accounts**, putting names, email addresses, phone numbers, and physical addresses into circulation. The stolen records came from a **Salesforce** instance and were later posted on a dark web leak site after ransom demands were rejected. A smaller employee-directory subset also added **job titles** to the exposed set.

Incident Charter Communications hit by network compromise linked to ShinyHunters
Updated 26.05.2026 22:46 Scoring Support Contribution 1
Extortion Data Theft Extortion Incident Disclosed

**Charter Communications** confirmed a **data breach** tied to **ShinyHunters** extortion, with the company saying it is **alerting authorities** and that **no sensitive personal information** or **CPNI** was exfiltrated in recent activity. ShinyHunters claims the compromise began on **April 1** through **vishing** that hit an employee's **Microsoft Entra** account and led to exports from **Salesforce**. **Have I Been Pwned** later analyzed leaked data and said the incident affected **4.9 million accounts**, with exposed records including names, email addresses, phone numbers, and physical addresses.