INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

ShinyHunters Leaks 4.9M Charter Customer Records

| 2026-05-29 10:22 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
On May 29, 2026, ShinyHunters, a cybercrime gang, added Charter Communications to its "trophy shelf" after leaking the personal details of approximately 4.9 million customers, including names, addresses, phones, and emails. The breach occurred despite Charter's apparent refusal to pay ransom demands made by the extortion crew, which claimed to have stolen over 42 million records belonging to consumer and business customers. ShinyHunters used a tactic known as extortion, where they threatened to leak sensitive data unless their demands were met. As of now, Charter is investigating the incident and disputing the sensitivity of the exposed data, while millions of compromised customer records remain available for scammers and identity thieves to exploit.
Technical Mitigations AI-generated
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Salt TyphoonSalt Typhoon
Target & Sectors
NORTH_AMERICA NORTH_AMERICA telecommunicationstelecommunications
Incident Timeline
‎May 2026
ShinyHunters added Charter to its trophy shelf after leaking approximately 4.9 million customer records, which were reportedly part of China's Salt Typhoon espionage campaign.
threat_actor Salt Typhoon
‎2026/05/29
ShinyHunters dumped the personal details of 4.9 million Charter Communications customers after the US telecom giant declined to pay their extortion demands.
data_breach 42 records
data_breach 4.9 customer records
victims 4.9 customers
data_breach 85,000 records
Tactical Metrics
Metrics
data_breach
4,900,000
Customer Records
Metrics
data_breach
42,000,000
Records
Metrics
victims
4,900,000
Customers
Metrics
data_breach
85,000
Records
Intelligence Sources
The Register - Cybercrime 2026-05-29