Charter Communications confirmed a data breach affecting its Spectrum brand after refusing to pay a ransom demanded by the ShinyHunters group. The attackers leaked customer records following a deadline of May 27, 2026. The incident began on April 1 when voice phishing targeted an employee's Microsoft Entra account.
Voice phishing attack compromises Microsoft Entra account leading to massive data leak
The breach exposed data from at least 13 million individuals and nearly 10 million support tickets. Most of the stolen information originated from Spectrum Enterprise accounts. A separate internal directory containing approximately 85,000 employees was also compromised, revealing job titles, email addresses, and some home addresses.
ShinyHunters initially claimed to possess between 40 and 42 million records. Cybernews reported that the dataset likely contains duplicates. Have I Been Pwned independently verified approximately 4.9 million unique email addresses within the leaked data.
A major dispute centers on whether Customer Proprietary Network Information was stolen. Charter Communications stated that no sensitive personal information or CPNI data left their systems. ShinyHunters claims to have exfiltrated this specific type of customer data.
This event underscores the security risks associated with corporate identity systems and social engineering methods. Targeting individual accounts through voice phishing can grant attackers substantial access to internal networks. Users are advised to regularly check their accounts for suspicious behavior after security incidents like this one.



Discussion
0 comments
Log in to join the thread with a thoughtful take, question, or correction.