Charter confirms data breach after ShinyHunters extortion threat
Charter says it suffered a breach, but denies sensitive customer data was exfiltrated after ShinyHunters threatened to leak stolen records.
Intelligence analysis by GPT-5.4 Mini

Charter says it is notifying authorities after a security incident tied to ShinyHunters, while denying that sensitive personal or CPNI data was stolen. The extortion group claims it accessed Charter through a vishing-led account compromise and pulled data from Salesforce.
A big phone and internet company says someone broke into part of its systems. The company says the thief did not take the most private kinds of customer information.
The bad actors say something different. They claim they tricked a worker, got into a work account, and copied a lot of customer records from a sales tool.
It is like someone sneaking into a store office with a borrowed key, then threatening to post copies of the filing cabinet unless the store pays up.
Analysis
What Charter confirms
Charter Communications, one of the largest broadband providers in the U.S., says it suffered a data breach and is working with authorities. In its statement to BleepingComputer, the company said no sensitive personal information or customer proprietary network information was exfiltrated as a result of the recent activity.
What ShinyHunters claims
The report says Charter was listed on the ShinyHunters leak site, where attackers claimed to have taken 40 million records tied to consumer and business customers. ShinyHunters told BleepingComputer it entered Charter’s environment on April 1 through a voice phishing attack that compromised an employee’s Microsoft Entra account. From there, the group says it exported records from Salesforce and took names, email addresses, addresses, phone numbers, phone type, plan details, some CPNI, and customer support ticket data.
Why this fits the current extortion pattern
The article places Charter inside a broader campaign ShinyHunters has used for months: trick an employee or BPO agent into handing over SSO access, then pivot into connected SaaS tools like Salesforce, Microsoft 365, Google Workspace, Slack, Adobe, Atlassian, Zendesk, and Dropbox. The stolen data is then used as leverage in an extortion demand.
The key tension here is between Charter’s denial of sensitive data theft and the threat actor’s much broader claims. The article does not resolve that dispute; it only shows that Charter acknowledges an incident and ShinyHunters is using it to apply pressure.
Key points
- Charter says it suffered a breach and is alerting authorities.
- The company says no sensitive personal information or CPNI was exfiltrated.
- ShinyHunters claims it stole millions of customer records through a compromised Microsoft Entra account.
- The group says it used access to Charter’s Salesforce instance to export data and extort the company.
- The case fits a wider pattern of social-engineering attacks against corporate SSO accounts.



