Charter Communications data breach affects 4.9 million accounts
ShinyHunters says it stole data from Charter Communications, and Have I Been Pwned says the leak affects 4.9 million accounts.
Intelligence analysis by GPT-5.4 Mini
Charter Communications confirmed a breach after attackers reportedly got in through a vishing attack and a compromised Microsoft Entra account. The stolen data was later leaked, and Have I Been Pwned says 4.9 million accounts were affected.
Charter is a big phone and internet company. Thieves tricked a worker into opening a door for them, then took a pile of records from the company’s computer tools.
Think of it like someone sneaking into a school office by pretending to be a repair person, then copying a huge stack of student files. The article says millions of account records were later leaked online.
Charter says the worst private details were not taken, but the leaked data still included names, email addresses, phone numbers, and home addresses. That makes it a serious privacy problem for many people.
Analysis
What happened
Charter Communications confirmed that it suffered a breach earlier this week, and BleepingComputer reports that the ShinyHunters extortion gang claimed responsibility. According to the article, the group says it got into Charter on April 1 through a voice phishing attack that compromised an employee’s Microsoft Entra account.
What was taken
ShinyHunters claimed it used that access to steal 42 million records from Charter’s Salesforce instance. The list the group described included customer and business names, email addresses, physical addresses, phone numbers, phone types, plan details, support ticket data, and some CPNI data. Charter, however, said no sensitive personal information or customer proprietary network information was exfiltrated as a result of the recent activity.
Have I Been Pwned analyzed leaked material and said the incident affected 4.9 million accounts. Its breakdown says the exposed records included unique email addresses, names, phone numbers, and physical addresses, with about 85,000 employee-directory records also containing job titles.
Why the story matters
The case highlights a familiar pattern in modern breaches: a social engineering call, access to a cloud identity account, then large-scale data theft from a connected SaaS system. The article also notes that ShinyHunters has been targeting Salesforce customers widely over the past year, and that the FBI has warned victims not to assume ransom payment will prevent resale or repeat extortion.
Charter is also mentioned in the context of the Salt Typhoon telecom intrusions, which underscores how major carriers can face multiple threat tracks at once: criminal extortion on one side and state-backed espionage on the other.
Key points
- Charter confirmed a breach and said it alerted authorities.
- ShinyHunters claimed it used vishing and a compromised Microsoft Entra account to get in.
- Have I Been Pwned says the leaked data affected 4.9 million accounts.
- The exposed records included names, emails, phone numbers, and physical addresses.
- The article places the breach in the context of broader ShinyHunters Salesforce targeting and telecom intrusions.



