Charter Communications, the parent company of Spectrum, has confirmed a data breach after the ShinyHunters extortion group threatened to release stolen customer data. The breach, which began around April 1, 2026, was initiated through a voice phishing (vishing) attack that compromised a Charter employee’s Microsoft Entra account.

ShinyHunters claimed to have acquired over 42 million records, though Charter states at least 13 million customer records were exposed along with 27,000 employee records. After gaining initial access through the compromised Entra account, the attackers pivoted into Charter’s Salesforce environment and exported customer records including names, email addresses, physical addresses, phone numbers, account plan details, and support ticket data. Charter denies that sensitive personal information or customer proprietary network information (CPNI) was exfiltrated, though ShinyHunters disputes this.

Source

Reporting from eSecurity Planet, Privacy Guides, and SafeState.

Commentary

This is the second major ShinyHunters breach making headlines in the same week — alongside Carnival — and it follows an identical playbook: vish an employee, compromise their identity provider credentials, then pivot to connected SaaS platforms. The Entra-to-Salesforce lateral movement is particularly concerning because it highlights how tightly integrated cloud environments create blast radius problems that most orgs aren’t monitoring for.

The Charter and Carnival breaches together paint a clear picture of ShinyHunters systematically targeting Salesforce environments through identity-based attacks. If your org uses Entra + Salesforce, this is your wake-up call to audit those integration points and enforce phishing-resistant MFA across the board.

By Allan