Data Leak
Incident
Charter customer data leak after vishing-led Salesforce access
Updated 29.05.2026 11:29
Case score 76
Score breakdown
- Total
- 76
- Lead score
- 72
- Support bonus
- +4 / 20
- Scoring support
- 1
- Context members
- 0
Top contributors
- Data Leak Confirmed public leak with the strongest affected-account count and exposed-data detail. base
- Incident Supplies the same Charter event's initial access, SaaS path, actor claim, and active response details. support
Case score 76
Members 2
Latest activity 29.05.2026 11:29
Members 2
First seen 26.05.2026 22:46
Last seen 29.05.2026 11:29
Updated 29.05.2026 11:29
Overview
**Charter Communications** customer data was leaked after attackers used **vishing** to compromise an employee's **Microsoft Entra** account and reach the company's **Salesforce** environment. The exposed set is confirmed at **4.9 million accounts**, and the published data includes names, email addresses, phone numbers, physical addresses, and a smaller employee-directory subset with job titles.
Available material ties the intrusion and leak to **ShinyHunters** and says publication followed rejected ransom demands. Charter is alerting authorities and disputes parts of the theft narrative, so the public leak is confirmed while the full exfiltration scope remains contested.
Attackers used **vishing** to compromise a **Charter Communications** employee's **Microsoft Entra** account, reach the company's **Salesforce** environment, and steal customer data in early April. Available material ties the intrusion and the later public leak to **ShinyHunters**, with the leaked dataset appearing after ransom demands were rejected. The confirmed public exposure covers **4.9 million accounts** and includes names, email addresses, phone numbers, physical addresses, and a smaller employee-directory subset with job titles.
The incident record and the leak record describe the same sequence: initial account compromise, access to cloud records, and later publication of stolen data. The actor claimed to have taken **42 million records** from Charter's Salesforce instance, but available evidence firmly confirms the leaked set at **4.9 million accounts** rather than the larger claim. The exposed data spans consumer and business customer information, increasing the risk of follow-on phishing, account abuse, and identity misuse.
Charter said it is alerting authorities and following security protocols, and it disputed parts of the actor's theft narrative by saying no sensitive personal information or **CPNI** was exfiltrated in the recent activity. That leaves the current picture as a confirmed large customer-data leak with a still-contested full exfiltration scope. No software vulnerability is identified in the available material; the known access path is social engineering against identity access that led to SaaS data exposure.
Signals
10 derivedImpact signals
Affected
42 million records claimed
Affected
4.9 million accounts
Affected
40 million records (claimed)
Affected impact
Affected
4.9 million accounts
Exposed data
Victims/regions
Victim region
United States
Remediation
Patch
No Patch
Status
Incident status
Disclosed
Threat context
Actor
Shinyhunters
Data exposure
Leak status
Fully Leaked
Data
Email Addresses
Data
Phone Numbers
Data
physical addresses
Member happenings
2 related
Data Leak
Charter Communications Salesforce data leak exposes 4.9 million accounts
Data Type
Email Addresses
Data Type
Phone Numbers
Data Status
Fully Leaked
Patch
No Patch
Data Leak
Charter Communications Salesforce data leak exposes 4.9 million accounts
Data Type
Email Addresses
Data Type
Phone Numbers
Data Status
Fully Leaked
Patch
No Patch
Incident
Charter Communications hit by network compromise linked to ShinyHunters
Extortion
Data Theft Extortion
Incident
Disclosed
Incident
Charter Communications hit by network compromise linked to ShinyHunters
Extortion
Data Theft Extortion
Incident
Disclosed