Skip to content
NetarxImpact Database
Vishing (Voice Phishing)UnknownConfirmed

Charter Communications breach of 4.9M accounts began with an Entra vishing call

Charter Communications (Spectrum) · Telecom · United States · April 1, 2026

People or records affected
4,900,000
4.9M as reported

What happened

ShinyHunters compromised an employee's Microsoft Entra account at Charter Communications through a voice phishing attack on 1 April 2026 and reached the company's Salesforce instance. Have I Been Pwned counted 4.9 million unique accounts in the leaked dataset; the attackers claimed 42 million records. Exposed fields included names, email and physical addresses, phone numbers and plan information, plus roughly 85,000 internal employee directory rows. Charter refused the ransom and the data was published.

How the deception worked

The call targeted a single employee's Microsoft Entra identity. Posing as internal support, the caller drove the target through a login that was actually the attacker's session, capturing the credential and the multi-factor response together. Entra then federated the attacker into Salesforce, where Charter kept sales tooling covering current, past and prospective business customers. Charter disputed the attackers' claim that customer proprietary network information was taken, saying only those sales tools were affected.

The control that would have caught it· our reading, not a claim from the sources

Phishing-resistant MFA on the identity provider is the single control that stops one talked-out login becoming an entire CRM; downstream SaaS should also enforce its own device and network conditions rather than trusting the federation alone.

Sources (2)

  1. Charter Communications data breach affects 4.9 million accounts
    BleepingComputer·bleepingcomputer.comOpen ↗
  2. Charter confirms Spectrum data breach after ShinyHunters claims hack
    Fox News·foxnews.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.