EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/2026-charter-communications-shinyhunters-breach
038/430

File EL-0393HighResolvedData Breach / Extortion with Data Exfiltration

Charter Communications (Spectrum) Data Breach

Also filed as ShinyHunters Charter Hack · Charter Spectrum Customer Data Leak · $4.9M Ransom Refusal Breach

The ShinyHunters extortion gang breached U.S. telecommunications giant Charter Communications (Spectrum) and stole personal information belonging to 4.9 million customers. After Charter refused to pay the $4.9 million ransom demand, ShinyHunters leaked the stolen data publicly on their leak site.

  • #telecommunications
  • #pii
  • #customer-data
  • #vishing
  • #sso-compromise
  • #extortion
  • #ransom-refusal
Notoriety8/10
Event
1 Apr 2026
Disclosed
26 May 2026
Target
Charter Communications
Actor
ShinyHunters
Scale
4.9M people
Status
Resolved

01Summary

In early April 2026, the ShinyHunters extortion group gained unauthorized access to Charter Communications' systems and exfiltrated customer data. The attackers initially demanded a $4.9 million ransom to prevent the data from being released. Charter Communications refused to pay the ransom, and ShinyHunters subsequently leaked the stolen records on their leak site. The breach was publicly confirmed by Charter Communications in late May 2026, and the data was added to Have I Been Pwned on May 28, 2026, listing 4.9 million affected accounts. The incident follows ShinyHunters' established pattern of targeting major U.S. corporations via social engineering and SSO compromise, then extorting them under threat of data leak.

02Background

Charter Communications is one of the largest telecommunications and media companies in the United States, operating the Spectrum brand. It provides cable television, internet, and phone services to over 30 million customers across 41 states. Major telecom companies hold extensive personal data on their customers, making them high-value targets for extortion-focused cybercriminal groups like ShinyHunters.

03Key revelations

  1. 01Charter Communications refused to pay the $4.9 million ransom, resulting in the public release of 4.9 million customer records.
  2. 02Telecommunications companies remain a primary target for extortion-focused cybercriminal groups.
  3. 03ShinyHunters' 2026 campaign continues to target major U.S. corporations through social engineering and SSO compromise.

04Technical analysis

The attack followed ShinyHunters' established 2025-2026 playbook, likely involving social engineering (vishing) to compromise employee credentials, followed by SSO platform exploitation (Okta or similar) to gain broad access to internal systems and customer databases. The data was then exfiltrated in bulk before ransom demands were made. The exact initial access vector was not publicly detailed by Charter.

Attack vector
Social engineering / Vishing leading to credential compromise
Attack method
Data exfiltration, extortion, and public leak
Initial access
Social engineering (likely vishing)
Lateral movement
SSO credential abuse
Exfiltration
Bulk data extraction

05Threat actor

ShinyHunters is a prolific cybercriminal/extortion group known for targeting large corporations and high-value datasets for financial gain through ransomware and data extortion. In 2026, the group has conducted an aggressive, multi-sector campaign targeting telecommunications, healthcare, education, and retail companies across the United States.

Aliases

  • SH
  • Scattered LAPSUS$ Hunters

Attribution sources

  • ShinyHunters leak site
  • Charter Communications SEC filing
  • BleepingComputer
  • Have I Been Pwned

06Victims and impact

Countries affected

  • United States

07Data exposed

Data types

  • PII
  • Names
  • Email addresses
  • Phone numbers
  • Account information
  • Service addresses

08Financial damage

No ransom paid; data leaked publicly. Regulatory fines, class-action lawsuits, and reputational damage expected.

09Timeline

  1. 2026-04-01Approximate date of initial breach and data exfiltration.
  2. 2026-05-26Charter Communications publicly confirms the breach after ShinyHunters extortion threat.
  3. 2026-05-28Breach listed on Have I Been Pwned with 4.9 million accounts; data leaked after ransom refusal.

10Reaction and fallout

Public reaction

Concern among Spectrum customers over exposed personal data and increased risk of phishing and identity theft.

Political impact

Renewed calls for stronger telecommunications cybersecurity regulations and mandatory ransom payment reporting.

11Legal

Ongoing investigations; class-action lawsuits anticipated.

Civil lawsuits

  • Anticipated class-action lawsuits related to data privacy and security failures

12Significance and legacy

Significance

Part of ShinyHunters' massive 2026 extortion campaign targeting major U.S. corporations across telecommunications, education, healthcare, and retail sectors. The Charter breach demonstrates the group's capability to breach critical national telecommunications infrastructure and the consequences of ransom refusal.

Legacy

Further highlights the vulnerability of major U.S. telecommunications infrastructure to sophisticated social engineering attacks and the growing trend of data extortion as a primary cybercrime model.

13Disclosure and media

Authentication
ShinyHunters leak site posting and Charter Communications SEC filing

Publishing organisations

  • BleepingComputer
  • Have I Been Pwned
  • SecurityWeek

14Related files

Related events

  • 2026-canvas-instructure-breach
  • 2026-medtronic-breach
  • 2026-match-group-breach

15Field notes

  1. 01Charter refused to pay the $4.9 million ransom, resulting in the full public release of the stolen customer data.
  2. 02The breach was part of a broader ShinyHunters campaign in 2026 that also targeted Instructure (Canvas), ADT, Medtronic, Match Group, 7-Eleven, and McGraw Hill.

16Resolution

Data was publicly leaked after Charter refused the ransom. Charter Communications notified affected customers and began providing identity protection services.

17Sources

Official documents

  • Charter Communications data breach notification
  • SEC filing

References

  1. [1]BleepingComputer: Charter Communications data breach affects 4.9 million accounts
  2. [2]BleepingComputer: Charter confirms data breach after ShinyHunters extortion threat
  3. [3]Have I Been Pwned - Charter Communications breach listing
  4. [4]SecurityWeek coverage
Fact sheetEL-0393

Dates

Event
1 Apr 2026
Started
1 Apr 2026
Discovered
1 Apr 2026
Disclosed
26 May 2026
Ongoing
No

Target

Organisation
Charter Communications, Inc.
Type
Technology Company
Sector
Telecommunications
Country
United States

Actor

Name
ShinyHunters
Type
Criminal Gang
Motivation
Financial gain through data extortion; demanded $4.9 million ransom, leaked data when refused.
Attribution
High
Status
Active
Arrested
No
Convicted
No

Data

People
4,900,000
Records
4,900,000
Sensitivity
High
Published
Yes
Sold (dark web)
Yes

Money

Ransom asked
$4,900,000
Crypto
Likely (standard for ShinyHunters extortion)

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.