The ShinyHunters extortion gang claimed responsibility for hacking Charter Communications on April 1 via a voice phishing attack that compromised an employee’s Microsoft Entra account. After Charter refused to pay a ransom, the group leaked data it said it stole from the company’s Salesforce instance.
ShinyHunters asserted it obtained 42 million customer records containing names, email addresses, physical addresses, phone numbers, phone types, plan details, support ticket information, and some customer proprietary network information (CPNI). Charter Communications denied that any CPNI or sensitive personal information was exfiltrated. "No sensitive personal information (PI) or customer proprietary network information (CPNI) data was exfiltrated by the threat actor as a result of recent activity," a Charter spokesperson told BleepingComputer.
Data breach monitoring service Have I Been Pwned analyzed the leaked dataset and verified the exposure of 4.9 million unique email addresses, along with associated names, phone numbers, and physical addresses. The analysis also found that approximately 85,000 records came from an internal employee directory and included job titles.
Charter stated that only sales tools used for managing current, past, and prospective business customers were affected. "We are aware of the situation, following our security protocols, and are working with appropriate authorities. Only sales tools used to manage current, past, and prospective business customers were impacted; no CPNI or sensitive PI was released by the threat actor," the Charter spokesperson said.
Charter Communications, which operates under the Spectrum brand, serves more than 32 million customers across 41 U.S. states and has over 92,000 employees. The company alerted authorities about the incident.
ShinyHunters has targeted Salesforce customers globally over the past year, claiming breaches of hundreds of companies and the theft of billions of records through campaigns involving Salesforce Aura and Salesloft Drift. The FBI has advised organizations not to pay ransom demands from ShinyHunters, noting that payment does not ensure stolen data will be withheld from public release or further exploitation.
forum Comments (0)
No comments yet. Be the first to comment.