news.mlab.sh
Back to the feed
data-breach

Charter Communications data breach affects 4.9 million accounts

High
Summary

Charter Communications experienced a data breach impacting approximately 4.9 million accounts following a sophisticated attack by the ShinyHunters extortion gang. The attackers gained access through a voice phishing (vishing) attack targeting an employee's Microsoft Entra account and subsequently exfiltrated data from Charter's Salesforce instance. While Charter initially denied the theft of sensitive customer information, the leaked data confirmed the exposure of personal details like email addresses and physical addresses.

The breach, which occurred in early April, was facilitated by ShinyHunters exploiting a compromised employee account to access Charter’s Salesforce instance. The gang stole a significant amount of data, including customer names, email addresses, physical addresses, phone numbers, and plan information. Following Charter’s refusal to pay a ransom, ShinyHunters leaked the stolen data via a dark web leak site. Have I Been Pwned subsequently analyzed the data, confirming the impact on 4.9 million accounts and revealing additional details such as job titles and internal employee directory information. The FBI has advised victims not to pay ransoms, highlighting the potential for further exploitation of the stolen data. Furthermore, the incident is linked to a broader campaign by ShinyHunters targeting Salesforce customers globally, and a separate, concurrent attack by a Chinese state-backed threat group known as Salt Typhoon, impacting multiple telecom companies across the US and internationally.

Read the full article at BleepingComputer