Charter Communications — vishing-led Salesforce CRM breach, ShinyHunters extortion
ShinyHunters claims 42 million Charter customer records exfiltrated from Salesforce after vishing an employee into surrendering their Microsoft Entra account.
- Target
- Charter Communications — vishing-led Salesforce CRM breach, ShinyHunters extortion
- Date public
- 25 May 2026
- Sector
- Telecoms
- Attack type
- Phishing
- Threat actor
- ShinyHunters
- Severity
- High
- Region
- United States
Charter Communications, the US cable giant behind the Spectrum brand, was breached in April 2026 by ShinyHunters, the extortion crew running a year-long campaign against corporate Salesforce databases. The attackers did not break through a firewall. They phoned an employee, talked past identity checks, and took over that person's Microsoft Entra login. That single identity was enough to reach Charter's Salesforce environment and export customer records in bulk — the attackers claim 42 million of them. Charter says no sensitive personal information or CPNI (the FCC-regulated call and service data that carriers are legally bound to protect) was taken. ShinyHunters says otherwise. That dispute, not the raw record count, is what makes this breach legally significant, and it is already in front of the courts.
Charter Communications, the second-largest US cable operator and parent of the Spectrum brand, confirmed a data breach on 25 May 2026 after the extortion group ShinyHunters listed the company on its leak portal and set a 27 May negotiation deadline. The group claimed the theft of more than 42 million customer records. Charter’s confirmation was narrow and carefully worded, and the gap between what the attackers say they took and what the company concedes has become the defining feature of the incident.
What happened
By the threat actor’s own account, initial access dates to around 1 April 2026. ShinyHunters describe phoning a Charter employee, talking their way through identity verification, and converting that social-engineering call into control of the employee’s Microsoft Entra account. From that identity foothold the attackers reached Charter’s Salesforce environment and exported customer records in bulk. The listing puts the haul at more than 42 million records and claims the dataset contains names, email addresses, physical addresses, phone numbers, plan details, customer proprietary network information (CPNI) and support-ticket history.
Charter’s public statement asserts that “no sensitive personal information (PI) or customer proprietary network information (CPNI) data was exfiltrated by the threat actor.” The construction is precise and leaves a large gap. It neither confirms nor denies the theft of the bulk of the claimed dataset — names, addresses, phone numbers, plan and support data — and it stakes the company’s position on two specific legal categories. The company says it is coordinating with law enforcement and notifying affected individuals as required.
That framing has not held the story still. The first class-action complaint, Kent v. Charter Communications, was filed in Connecticut federal court on 1 June 2026, and further class actions had accumulated by mid-July. The litigation turns directly on the CPNI question, because for a telecoms carrier that acronym is not reassurance boilerplate — it is a regulated category with its own breach-notification regime.
How it worked
Charter sits inside the largest social-engineering campaign of the year. Across April and May, ShinyHunters dumped or extorted data from Carnival, Vimeo, 7-Eleven, Cushman & Wakefield, Medtronic, Instructure, Pitney Bowes, DentaQuest and roughly forty other organisations, all through variations on the same theme: talk a human into surrendering access, reach a Salesforce customer store, export at scale, list on the portal. Google’s Threat Intelligence Group tracks the initial-access activity as UNC6040 and the follow-on extortion as UNC6240, both of which keep claiming the ShinyHunters name; Microsoft has since mapped a year of this activity to three distinct Salesforce attack paths.
The Charter variant is worth separating from the cluster’s most common technique. In the Carnival pattern, the attackers coax an employee into approving an OAuth device-flow code tied to an attacker-controlled Salesforce Data Loader, which then holds a valid token and paginates through Account, Contact, Case and User objects. Charter’s reported chain skips the malicious connected app entirely. Rather than tricking the victim into authorising a rogue application, the attackers took over the underlying Microsoft Entra identity. Once that identity is theirs, the Salesforce session is trusted natively, and the bulk export looks like an authenticated user doing heavy but legitimate CRM work. Both routes lead to the same place — a customer-record store exported wholesale — but the identity-provider compromise is the harder one to catch, because there is no third-party app consent event to flag.
Much of the cluster’s tradecraft traces upstream to the Salesloft/Drift OAuth-token theft of August 2025, which leaked credentials for a Salesforce-connected application across roughly 760 customer tenants and handed ShinyHunters both a working recipe and a stock of tokens to harvest. Charter’s route is the direct-identity cousin of that supply-chain shortcut.
The CPNI wrinkle is what makes Charter distinct from every retail and cruise-line entry in the cluster. Customer proprietary network information — the call, service and usage data a carrier holds — sits under a specific Federal Communications Commission regime with mandatory breach-notification timelines. When customer records for a telecoms subscriber base pass through a Salesforce CRM, CPNI can travel with them. Charter’s flat “no CPNI” assertion is therefore a legal position as much as a technical one, and it is the exact claim the plaintiffs intend to test against whatever the eventual forensic scope shows.
Timeline
Initial access is dated to around 1 April 2026 on the attacker’s account, and the intrusion went undetected for several weeks. In late May ShinyHunters listed Charter on its extortion portal with a 27 May deadline. Charter confirmed the breach publicly on 25 May. On 1 June the first class action, Kent v. Charter, was filed in Connecticut; by mid-July additional class actions had been consolidated into the litigation. As of this writing Charter has not publicly resolved a materiality determination through an SEC 8-K, and the state attorney-general and FCC notification picture is still firming up.
What defenders should learn
The single most useful detail here is the access path. There was no malware, no exploited vulnerability, and — unlike much of the rest of the cluster — no rogue application consent to point at afterwards. A phone call became an Entra identity, and an Entra identity reached a customer database of tens of millions. The defensive question the incident poses is a blast-radius one: what should a single compromised identity, however privileged, be able to address in one working day?
That question sits on top of the CRM export surface itself. A bulk pull of tens of millions of Account and Contact records is a fundamentally different behaviour from a support agent opening tickets, and it is detectable as a volume-and-rate anomaly if the telemetry exists and someone is watching it. For a regulated carrier there is a third lesson layered on the first two, which is that the accuracy of the CPNI claim in the first disclosure will be judged against the forensic record later — and the narrower the initial statement, the more load it has to bear.
Sources
See the source list above. BleepingComputer and SC Media carry the most reliable contemporaneous reporting of the extortion listing and Charter’s confirmation; CyberInsider holds the fullest account of the 42-million-record claim and the CPNI dispute. Google/Mandiant’s UNC6040 write-up and Microsoft’s mapping of the year-long ShinyHunters activity provide the authoritative technical context for the campaign this breach belongs to.
Sources
- BleepingComputer — Charter confirms data breach after ShinyHunters extortion threat (25 May 2026) // reporting
- Google Cloud / Mandiant — UNC6040 proactive hardening recommendations // analysis
- The Hacker News — Microsoft maps three Salesforce attack paths tied to a year of ShinyHunters activity // analysis
- CyberInsider — Charter Communications confirms data breach as hackers threaten leak of 42 million records // reporting
- SC Media — ShinyHunters extorts Charter Communications after data breach // reporting