Threat Intelligence

📞 Charter Breach: 40M Records Stolen via Voice Phishing

By Ateeq Y Tanoli, BestPasswordGenerator.org · 29 May 2026 · 10 min read · 2,030 words

Charter Communications, one of the largest broadband providers in the United States operating the Spectrum brand, has confirmed a data breach after the ShinyHunters extortion group claimed to have stolen 40 million customer records. The attackers gained access through a voice phishing (vishing) attack that compromised an employee's Microsoft Entra single sign-on account — a method that bypasses traditional password defences entirely.

This attack proves something we have been warning about throughout 2026: having a strong password is no longer enough. When attackers can call up an employee, trick them into handing over SSO credentials via a phone call, and then export millions of records from cloud applications, the entire model of password-only security collapses.

Here is exactly what happened at Charter, how vishing works, what the stolen data means for affected customers, and — most importantly — the concrete steps you need to take to protect yourself from this type of attack.

What happened at Charter Communications

On April 1, 2026, the ShinyHunters extortion group launched a voice phishing campaign targeting Charter Communications. According to information shared with BleepingComputer, the attackers called Charter employees and used social engineering to trick one of them into providing access to their Microsoft Entra (formerly Azure Active Directory) account.

Once inside the SSO account, the attackers pivoted to Charter's Salesforce instance — a customer relationship management platform containing millions of consumer and business records. They exported data including:

Charter initially claimed that "no sensitive personal information or customer proprietary network information was exfiltrated," but the ShinyHunters group contradicted this, stating that CPNI was among the stolen records. In total, the attackers claim to have taken 40 million records from Charter's Salesforce system.

The breach went public when Charter appeared on the ShinyHunters data leak site with a ransom demand. Charter acknowledged the incident in a statement, saying it was "aware of the situation, following our security protocols and in the process of alerting appropriate authorities."

Stay informed about the latest data breach statistics and password security trends to understand how these attacks fit into the broader threat landscape.

What is vishing and why is it so effective?

Vishing — short for voice phishing — is a social engineering attack conducted over the phone. Instead of sending a deceptive email (traditional phishing) or a text message (smishing), the attacker calls the target directly and impersonates a trusted party.

In the Charter attack, ShinyHunters called an employee and posed as an IT support representative. Using stolen internal knowledge and confidence tricks, they convinced the employee to share their Microsoft Entra login credentials and multi-factor authentication codes.

There are several reasons vishing is alarmingly effective:

Voice commands trust. Humans are conditioned to trust voice conversations. When someone calls and sounds professional, uses the right internal terminology, and creates a sense of urgency, most people comply before their rational brain catches up.

Vishing bypasses email security. Unlike phishing emails that spam filters can catch, a phone call has no headers to analyse, no links to scan, and no sender domain to verify. Traditional email security tools are completely blind to vishing.

Multi-factor authentication can be socially engineered. Even when MFA is enabled, an attacker who has convinced an employee to read out a one-time code over the phone can bypass it. The FBI has warned repeatedly that MFA fatigue and vishing are defeating the security that MFA was designed to provide.

Vishing targets the human layer. Charter likely had strong technical controls — firewalls, endpoint detection, SIEM monitoring. But none of those defend against an employee voluntarily handing over credentials over the phone. The human layer is always the weakest.

For a deeper look at how MFA prompt bombing works alongside vishing attacks, see our coverage of MFA prompt bombing attacks surging in 2026.

Why Salesforce and SSO are prime targets

The Charter breach is part of a much larger pattern. Over the past year, ShinyHunters has been systematically targeting companies that use Salesforce and single sign-on (SSO) identity providers like Microsoft Entra, Okta, and Google Workspace.

The attack chain follows a consistent playbook:

  1. Reconnaissance — The attackers research their target, identifying employees with access to Salesforce and other cloud applications. LinkedIn, corporate websites, and data broker services provide all the information needed.

  2. Vishing call — The attackers call the employee, impersonating IT support, a vendor, or a senior executive. They use urgency ("your account will be locked") and authority to extract credentials.

  3. SSO compromise — Once inside one SSO account, the attackers have access to every cloud application connected to that identity provider. Salesforce, Microsoft 365, Google Workspace, Slack, Zendesk, and Atlassian are all reachable through a single set of stolen credentials.

  4. Data exfiltration — From Salesforce, the attackers run automated exports. ShinyHunters has used tools like Salesloft and other integration platforms to steal OAuth tokens that give them persistent access to Salesforce instances without needing to log in again.

  5. Extortion — With terabytes of stolen data, the attackers post a sample on their leak site and demand a ransom. If the company refuses, the data is leaked publicly or sold to other cybercriminals.

This is the same playbook used in the GitHub breach linked to the TanStack npm supply-chain attack and the Canvas breach affecting 275 million students. The attack chain is remarkably consistent across all these incidents.

ShinyHunters has also targeted Salesloft and other integration companies specifically to steal OAuth tokens that enable credential-less access to Salesforce instances — meaning they do not even need a password to begin with.

How to protect yourself from vishing attacks

While the Charter breach affected corporate systems, the same vishing tactics can target individuals. Criminals call pretending to be your bank, your mobile provider, or your internet service provider, asking you to "verify your account" by sharing a code sent to your phone. That code is actually a password reset or MFA prompt.

Here are the practical steps you can take immediately:

Step 1: Never give out authentication codes over the phone.

No legitimate organisation will call you and ask for a one-time passcode. If someone calls and asks for a code "to verify your identity," hang up immediately. Call your bank or provider back using the number on the back of your card — not a number the caller gives you.

Step 2: Use a password manager to generate and store unique credentials.

If your password is leaked in one data breach, you want that password to work on exactly one account — not all of them. Generating a strong, unique password for every account ensures that a single credential leak cannot cascade into a full account takeover. Password managers like Bitwarden and 1Password also generate cryptographically strong passwords that are resistant to both brute-force and dictionary attacks.

Step 3: Enable phishing-resistant MFA where available.

Standard TOTP and SMS-based MFA can be bypassed by vishing (when the attacker tricks you into reading the code). FIDO2/WebAuthn security keys (YubiKey, Google Titan) cannot — there is no code to read out over the phone. For high-value accounts such as email, banking, and cloud services, use a hardware security key.

Step 4: Monitor your accounts for signs of compromise.

Run your email address through Have I Been Pwned regularly. Check your account "recent activity" or "devices" sections for unrecognised logins. If you see a login from an unfamiliar location, change your password immediately and revoke all active sessions.

Step 5: Set up a family security protocol.

If you manage accounts for family members — especially older relatives who are frequent targets of vishing — establish a verbal "safe word" that must be used before anyone shares sensitive information over the phone. This simple technique stops social engineering attacks cold because the attacker does not know the safe word. For an extra layer of protection when accessing accounts from public Wi-Fi, a VPN service encrypts your internet connection and keeps your online activity hidden from network-level snooping.

What the Charter breach means for your passwords

The Charter breach, like the Carnival Cruise data breach confirmed days earlier, delivers a clear message: passwords alone are an insufficient defence against modern threats.

When attackers can bypass passwords entirely through social engineering — by calling up an employee and convincing them to hand over their SSO credentials — the traditional advice of "use a strong password" covers only part of the problem. You also need:

The best password managers in 2026 include all of these features: unique password generation, secure storage, breach monitoring, and support for hardware security keys. They transform the impossible task of remembering 100+ unique passwords into a manageable, automated system.

If you use the same password for multiple accounts, the Charter breach puts you at risk even if you are not a Charter customer. Attackers who obtain credentials from one breach try them against every other service — this is called credential stuffing, and our credential stuffing surge 2026 guide explains why it is the fastest-growing attack vector this year.

For enterprise users managing credentials across teams, the lessons from Charter are particularly important. The attack did not break cryptography or exploit a software vulnerability — it tricked a human. Organisations should review their SSO configurations, restrict Salesforce data exports to authorised IP ranges, implement phone call verification protocols for support requests, and train employees specifically on vishing recognition.

FAQs

Do I need to worry about vishing if I use strong passwords?

Yes. Strong passwords protect against password cracking and credential guessing, but vishing bypasses passwords entirely by tricking you into handing them over. Think of your password as one layer in a defence-in-depth strategy — essential but not sufficient on its own.

Was Charter the only company affected by this vishing campaign?

No. ShinyHunters has conducted similar vishing and social engineering attacks against hundreds of companies worldwide, including Carnival Cruise Line (6 million records), Instructure/Canvas (275 million student records), and numerous Salesforce customers. The FBI has issued warnings about this group's widespread SSO-targeting campaign.

How do I check if my data was stolen in the Charter breach?

Visit Have I Been Pwned and search for your email address. If Charter notifies affected individuals, they will also send direct notifications. You can also check your accounts for signs of compromise — unexpected password reset emails, unfamiliar login locations, or devices you do not recognise.

Should I change my passwords after this breach?

Yes, regardless of whether you are a Charter customer. If you use any of the same passwords across multiple accounts, change them now. Using a password generator ensures every account gets a strong, unique credential. Enable MFA everywhere, and consider a hardware security key for your most sensitive accounts.

Can a phone call really bypass multi-factor authentication?

Yes. If an attacker calls you, claims to be your IT department, and asks you to read out a code sent to your phone "for verification," you are handing them your MFA code. This is why FIDO2 hardware security keys are considered phishing-resistant: instead of a sharable code, they use a cryptographic challenge-response protocol that cannot be relayed over the phone.

How many people fall for vishing attacks?

Studies suggest that 25-40% of targeted employees fall for well-executed vishing calls. In the 2026 Verizon DBIR, social engineering was a factor in 62% of all confirmed breaches, with phone-based attacks showing a median success rate 40% higher than email phishing.

What is the difference between phishing, smishing, and vishing?

Phishing uses deceptive emails, smishing uses SMS text messages, and vishing uses phone calls. All three aim to trick the target into revealing credentials or sensitive information. Vishing is considered the most dangerous because phone calls bypass email security filters and exploit the natural human trust in voice communication.

Generate a Free Strong Password →

More Password Security Tools

🔑 SecureKeyGen⚔️ TitanPasswords🔐 Free Strong Password⚡ Instant Password🗝️ Iron Vault Keys🔑 Random Pwd Tool👨‍👩‍👧‍👦 Safe Pass Builder🛡️ Trusty Password⚙️ StrongPassFactory🔑 SecureKeyGen.org📚 TrustyPassword.org
We use cookies to improve your experience. Learn more

🛡️ Security Picks This Week

Hand-picked security tools — updated weekly.

Thetis Pro-C FIDO2 Key

Thetis Pro-C FIDO2 Key

Budget USB-C/NFC security key with TOTP authenticator app.

Check price →
Yubico Security Key NFC

Yubico Security Key NFC

Budget-friendly 2FA key — USB-A & NFC, FIDO2 certified.

Check price →
TP-Link ER605 VPN Router

TP-Link ER605 VPN Router

Multi-WAN VPN gateway — secure every device on your network.

Check price →

As an Amazon Associate we earn from qualifying purchases.