AUTO-UPDATED

Charter Communications confirms data breach — ShinyHunters blamed after threat to leak user info online

Charter Communications has confirmed a security breach after the hacking group ShinyHunters claimed to have stolen 40 million customer records through a targeted voice phishing attack on April 1.

Key Points

  • The hacking group ShinyHunters claims to have exfiltrated 40 million customer records, including names, emails, addresses, and support ticket information.
  • Attackers allegedly gained unauthorized access to a Microsoft Entra account via a vishing scam and subsequently extracted data from a Salesforce instance.
  • Charter Communications confirmed the incident and is currently coordinating with relevant authorities to address the security breach.
  • The company stated that no sensitive personal information or customer proprietary network information was compromised during the event.
  • ShinyHunters is a prominent threat actor known for using social engineering and remote management tools to infiltrate corporate networks.

Why it Matters

This breach highlights the ongoing vulnerability of large telecommunications providers to sophisticated social engineering tactics that bypass traditional security perimeters. The incident underscores the critical need for robust identity verification protocols to prevent unauthorized access to sensitive customer databases stored in third-party platforms like Salesforce.
TechRadar Published by Sead Fadilpašić
Read original