Find notable cyber news and cases, enriched with sources, timelines, and signals.
Data Leak Incident

Charter customer data leak after vishing-led Salesforce access

Updated 29.05.2026 11:29
Case score 76
Members 2 First seen 26.05.2026 22:46 Latest activity 29.05.2026 11:29

Overview

**Charter Communications** customer data was leaked after attackers used **vishing** to compromise an employee's **Microsoft Entra** account and reach the company's **Salesforce** environment. The exposed set is confirmed at **4.9 million accounts**, and the published data includes names, email addresses, phone numbers, physical addresses, and a smaller employee-directory subset with job titles. Available material ties the intrusion and leak to **ShinyHunters** and says publication followed rejected ransom demands. Charter is alerting authorities and disputes parts of the theft narrative, so the public leak is confirmed while the full exfiltration scope remains contested.
Latest development Open development history 3 earlier developments ShinyHunters breaches Charter Communications on April 1 via vishing ShinyHunters claimed it breached Charter Communications on April 1 by using vishing to compromise an employee's Microsoft Entra account and reach the company's Salesforce environment, then said it used that access to steal customer and business records.
  1. Earlier development

    Have I Been Pwned confirms 4.9 million Charter Communications accounts were exposed

    Have I Been Pwned analyzed leaked Charter Communications data and said the incident affected 4.9 million accounts, exposing names, email addresses, phone numbers, physical addresses, and a subset of employee-directory records that included job titles.

  2. Earlier development

    ShinyHunters claims vishing access to Charter Communications on April 1

    ShinyHunters claims it breached Charter Communications on April 1 by using a voice phishing attack to compromise an employee's Microsoft Entra account and then export data from the company's Salesforce instance.

  3. Earlier development

    Charter Communications confirms a data breach and disputes exfiltration claims

    Charter Communications says it is alerting authorities and following security protocols after the ShinyHunters extortion threat, and states that no sensitive personal information or CPNI data was exfiltrated in recent activity. The attackers claim they stole 40 million records containing customer names, email addresses, addresses, phone numbers, plan information, some CPNI, and customer support ticket data.

Signals

Impact signals
Affected impact
Remediation
Status
Threat context
Data exposure

Threat actor context

1 listed

Technical intelligence

Existing Case data

Member happenings

Data Leak Charter Communications Salesforce data leak exposes 4.9 million accounts
Updated 29.05.2026 11:29 Lead Contribution 72
Data Type Email Addresses Data Type Phone Numbers Data Status Fully Leaked Patch No Patch

The **public leak** of **Charter Communications** data exposed **4.9 million accounts**, putting names, email addresses, phone numbers, and physical addresses into circulation. The stolen records came from a **Salesforce** instance and were later posted on a dark web leak site after ransom demands were rejected. A smaller employee-directory subset also added **job titles** to the exposed set.

Incident Charter Communications hit by network compromise linked to ShinyHunters
Updated 26.05.2026 22:46 Scoring Support Contribution 1
Extortion Data Theft Extortion Incident Disclosed

**Charter Communications** confirmed a **data breach** tied to **ShinyHunters** extortion, with the company saying it is **alerting authorities** and that **no sensitive personal information** or **CPNI** was exfiltrated in recent activity. ShinyHunters claims the compromise began on **April 1** through **vishing** that hit an employee's **Microsoft Entra** account and led to exports from **Salesforce**. **Have I Been Pwned** later analyzed leaked data and said the incident affected **4.9 million accounts**, with exposed records including names, email addresses, phone numbers, and physical addresses.