← Back to news

Charter confirms data breach after ShinyHunters extortion threat

BleepingComputer26/05/2026, 19:46
Read full article →

Summary

AI-Generated

Key Points:

  • Charter Communications has confirmed a data breach linked to the ShinyHunters extortion group, which threatened to leak stolen data unless a ransom is paid.
  • The breach reportedly involved access to an employee's Microsoft Entra account via a voice phishing (vishing) attack, leading to the export of millions of customer records from Salesforce, although Charter asserts that no sensitive personal information was exfiltrated.
  • Organizations should enhance their security awareness training, implement multi-factor authentication (MFA), and monitor for unusual access patterns to prevent similar attacks.

Technical Details: The breach occurred on April 1, with attackers utilizing vishing tactics to compromise an employee's Microsoft Entra account and subsequently accessing Salesforce data.

MITRE ATT&CK Techniques:

  • T1566.002 - Phishing: Vishing (Initial Access)
  • T1078 - Valid Accounts (Initial Access)
  • T1213 - Data from Information Repositories (Collection)

IOCs Mentioned: None mentioned

Join the discussion — sign up to comment, upvote, and save articles.

Discussion

or to comment
Loading...

Loading comments...

Join 5,000+ security professionals

Get access to curated threat intel, upvote articles, join discussions, and build your karma in the SOC community.