INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
ShinyHunters Leaks 4.9M Charter Customer Records
| 2026-05-29 10:22 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
On May 29, 2026, ShinyHunters, a cybercrime gang, added Charter Communications to its "trophy shelf" after leaking the personal details of approximately 4.9 million customers, including names, addresses, phones, and emails. The breach occurred despite Charter's apparent refusal to pay ransom demands made by the extortion crew, which claimed to have stolen over 42 million records belonging to consumer and business customers. ShinyHunters' tactics involve dumping stolen data online after a deadline for payment passes, as seen in this case where the gang updated its listing with a message stating that Charter failed to reach an agreement despite their "incredible patience." The incident is not Charter's first brush with high-profile intrusions, having been caught up in China's Salt Typhoon espionage campaign last year.
Technical Mitigations AI-generated
• Patch Charter's systems to address the vulnerability exploited by ShinyHunters, specifically addressing the issue with the internal staff directory.
• Use a threat intelligence feed like Have I Been Pwned to detect and alert on potential data breaches involving similar tactics as ShinyHunters.
• Block or hunt for IP addresses associated with ShinyHunters' known command-and-control servers.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Salt TyphoonSalt Typhoon
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
telecommunicationstelecommunications
Incident Timeline
May 2026
ShinyHunters added Charter to its trophy shelf after leaking approximately 4.9 million customer records, following the telecom provider's failure to reach an agreement with the attackers despite offers made by investigators.
Click on any entity below to view its context and source!
threat_actor
Salt Typhoon
The telecom provider was
among the organizations reportedly caught up in China's Salt Typhoon espionage campaign last year
, alongside a growing list of US telcos.
2026/05/29
ShinyHunters dumped the personal details of 4.9 million Charter Communications customers after the US telecom giant declined to pay their extortion demands.
Click on any entity below to view its context and source!
data_breach
42 records
Charter appeared on the ShinyHunters leak site earlier this month, with the extortion crew claiming to have stolen more than 42 million records belonging to consumer and business customers.
The listing, seen by
The Register
, warned: "Over 42M records containing PII have been compromised.
"Over 42M records containing PII have been compromised.
data_breach
4.9 customer records
Cyber-Crime
ShinyHunters adds Charter to trophy shelf after 4.9M customer records leak
Telco giant says no sensitive data was taken, though names, addresses, phones, and emails are now out there
ShinyHunters claims it has dumped the person…
ShinyHunters adds Charter to trophy shelf after 4.9M customer records leak.
victims
4.9 customers
According to
Have I Been Pwned
, the breach exposed the personal details of 4.9 million customers, including names, email addresses, phone numbers, and physical addresses.
data_breach
85,000 records
It says a smaller subset of roughly 85,000 records originating from an internal staff directory also contained job titles.
Tactical Metrics
Metrics
data_breach
4,900,000
Customer Records
Click for context!
Cyber-Crime
ShinyHunters adds Charter to trophy shelf after 4.9M customer records leak
Telco giant says no sensitive data was taken, though names, addresses, phones, and emails are now out there
ShinyHunters claims it has dumped the person…
ShinyHunters adds Charter to trophy shelf after 4.9M customer records leak.
Metrics
data_breach
42,000,000
Records
Charter appeared on the ShinyHunters leak site earlier this month, with the extortion crew claiming to have stolen more than 42 million records belonging to consumer and business customers.
The listing, seen by
The Register
, warned: "Over 42M records containing PII have been compromised.
"Over 42M records containing PII have been compromised.
Metrics
victims
4,900,000
Customers
According to
Have I Been Pwned
, the breach exposed the personal details of 4.9 million customers, including names, email addresses, phone numbers, and physical addresses.
Metrics
data_breach
85,000
Records
It says a smaller subset of roughly 85,000 records originating from an internal staff directory also contained job titles.
Intelligence Sources
The Register - Cybercrime
2026-05-29
ShinyHunters adds Charter to trophy shelf after 4.9M customer records leak
The Register - Cybercrime
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T07:31
Comprehensive Tactical Telemetry
Highly Correlated Entities
9x
organisation
Identified Entity
Cyber-Crime
entity
3x
tactic
Cyber Operation Type
Extortion
tactic
2x
target region
Target Country
United States
country
2x
timeline
Temporal Reference
2025/05/29
date
2x
data breach
Records
42,000,000
records
Contextual Telemetry
Context Block
3 METRICS
data breach
Customer Records
4,900,000
customer records
threat actor
APT Group
Salt Typhoon
actor
victims
Customers
4,900,000
customers
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.