Briefing

Charter Communications data breach affects 4.9 million accounts

security
by Sergiu Gatlan ·

Check for exposed Salesforce data, patch any vulnerabilities, and monitor for suspicious activity.

What to do now

Patch Salesforce security settings, enforce MFA on Microsoft Entra, review access logs, and notify affected customers.

Summary

Charter Communications confirmed a data breach that exposed 4.9 million accounts after the ShinyHunters extortion gang compromised an employee’s Microsoft Entra account via a vishing attack on April 1. The attackers then accessed Charter’s Salesforce instance and stole 42 million records, including customer names, email addresses, physical addresses, phone numbers, plan information, support ticket data, and some CPNI. Charter stated that no sensitive personal information or proprietary network data was exfiltrated, and the company has alerted authorities. The ShinyHunters gang later leaked the stolen data on a dark‑web site after Charter refused to pay the ransom.

The leaked data set contains 4.9 million unique email addresses, names, phone numbers, and physical addresses, with a subset of about 85 k records from an internal employee directory that also includes job titles. Charter’s breach is part of a broader wave of attacks by the Chinese state‑backed Salt Typhoon group that also impacted AT&T, Verizon, and other telecoms. The FBI has warned victims not to give in to ransom demands, citing the risk of data resale or further extortion. The incident highlights the need for stronger MFA and stricter access controls on cloud services such as Salesforce.

Key changes

  • 4.9 million accounts affected, including names, emails, phone numbers, addresses, and job titles
  • Breach began with a vishing attack compromising a Microsoft Entra employee account
  • Attackers stole 42 million Salesforce records, including customer names, emails, addresses, phone numbers, plan info, support tickets, and some CPNI
  • 85 k records from an internal employee directory included job titles
  • ShinyHunters leaked the data on a dark‑web site after Charter refused to pay ransom
  • Charter confirmed no sensitive personal information or proprietary network data was exfiltrated

Affects

enterprise

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting