The ShinyHunters extortion gang stole personal information from 4.9 million accounts after hacking U.S. telecom giant Charter Communications in early April, according to data breach notification service Have I Been Pwned.

Charter, which operates under the Spectrum brand, has more than 92,000 employees and provides internet, mobile, video, and voice services to over 32 million customers across 41 U.S. states. The company also reaches more than 57 million homes through its network.

Charter confirmed the breach earlier this week but said the attackers did not steal sensitive personal customer information. The company also said it had informed authorities about the incident.

“No sensitive personal information (PI) or customer proprietary network information (CPNI) data was exfiltrated by the threat actor as a result of recent activity,” Charter told BleepingComputer.

Although Charter has not officially blamed any group for the attack, ShinyHunters claimed responsibility. The gang told BleepingComputer that it breached Charter’s systems on April 1 through a voice phishing, or vishing, attack that compromised an employee’s Microsoft Entra account.

The attackers claimed they used that access to steal 42 million records from Charter’s Salesforce system. According to the gang, the stolen data included consumer and business customer names, email addresses, physical addresses, phone numbers, phone types, plan information, support ticket details, and some CPNI data.

After Charter allegedly refused to pay a ransom, ShinyHunters leaked the stolen documents on its dark web leak site. BleepingComputer contacted Charter again about the group’s claim that additional CPNI data was stolen, but the company referred back to its original statement.

READ
OpenAI Says Internal AI Test Accidentally Hacked Hugging Face During Cybersecurity Evaluation

Have I Been Pwned later analyzed the leaked data and confirmed that 4.9 million accounts were affected. The exposed information included names, email addresses, phone numbers, physical addresses, and, in some cases, job titles.

“The group later published the data, which exposed 4.9M unique email addresses along with names, phone numbers and physical addresses,” Have I Been Pwned said. It added that about 85,000 records appeared to come from an internal employee directory and also included job titles.

ShinyHunters has been targeting Salesforce customers over the past year, claiming attacks on hundreds of companies worldwide and the theft of billions of records through Salesforce-related data theft campaigns.

The FBI has recently advised victims of ShinyHunters not to pay ransom demands, warning that payment does not guarantee stolen data will be deleted or that attackers will not try to extort victims again.

Charter Communications was also previously impacted in a separate wave of telecom breaches linked to the Chinese state-backed hacking group known as Salt Typhoon, which also targeted AT&T, Verizon, Consolidated Communications, Windstream, Lumen, and telecom companies in several other countries.


Buy ExpressVPN with PayPal or Credit Card

Advertisement