Breach tracker

Breach report

Charter confirms breach after ShinyHunters claims, disputes sensitive data loss

ConfirmedDisclosed Updated United StatesTelecomBy Vivek Kumar
Records 4.9M emails (HIBP)Cause Social engineeringAttributed / claimed ShinyHunters
Conceptual illustration: An unbranded broadband modem with fibre-optic strands, anonymous service cards and a small network warning. Headline: CHARTER CYBER INCIDENT.

AI-generated illustration by CyberShitty. Not a photograph or a document from the organisations named.

Charter says no sensitive personal information or CPNI was taken. ShinyHunters claims 40 million records from Salesforce; HIBP loaded 4.9 million emails from the leak.

What happened

Charter Communications, which runs the Spectrum broadband and cable brand in the US, confirmed a data breach in late May 2026 after the ShinyHunters extortion group listed it on its leak site and threatened to publish stolen data. Charter told BleepingComputer it was following its security protocols and alerting authorities. The group later published the data, according to Have I Been Pwned (HIBP).

Confirmed vs. claimed

Confirmed by Charter: an incident occurred. Disputed by Charter: the company says no sensitive personal information or customer proprietary network information (CPNI, the call and service records US telecom law protects) was exfiltrated.

Claimed: ShinyHunters told BleepingComputer it got in on 1 April by vishing (voice phishing) an employee's Microsoft Entra account, then exported consumer and business records from Charter's Salesforce instance. It claims 40 million records with names, emails, addresses, phone numbers, plan details, some CPNI and support tickets. Charter has not confirmed the entry method or the count. HIBP says the published data held 4.9 million unique email addresses with names, phone numbers and addresses, plus about 85,000 employee directory records.

Who is affected

Spectrum consumer and business customers in the US, and some Charter staff. Charter has not said whether it will send notification letters.

What to do

  • Check your email address on Have I Been Pwned.
  • Expect calls or emails that pose as Spectrum support and quote your plan or address. Hang up and call the number on your bill.
  • Change your Spectrum password and turn on multi-factor authentication (MFA).
  • Never read out one-time codes to a caller.
  • See our guides on ShinyHunters extortion emails and what to do after a data breach notice.

Sources

More breaches in United States