On April 1, 2026, a Charter Communications employee in the United States received a phone call. The caller identified themselves as a member of IT support and walked the employee through a sequence of steps that ended with the attacker holding the employee's Microsoft Entra ID credentials. Charter Communications, trading as Spectrum, is one of the largest cable and broadband providers in the United States, with more than 32 million customer relationships across internet, television, mobile, and voice services.
Microsoft Entra ID is the identity layer Charter uses for single sign-on across its corporate software environment. Once the attacker authenticated with the compromised account, Charter's Salesforce instance became accessible without any further obstacle. ShinyHunters, a prolific data theft and extortion group, proceeded to run a Salesforce data export that pulled customer records out of the tenant in bulk. The group had used precisely this method at multiple other organisations in the preceding weeks, including Instructure, Cushman and Wakefield, 7-Eleven, ADT, and Vimeo. A vishing call, a harvested SSO credential, and a Salesforce export: the same three steps, the same outcome.
The data extracted from Charter's Salesforce environment reportedly includes full customer names, email addresses, physical service addresses, telephone numbers, Spectrum service plan details, and Customer Proprietary Network Information. A separate table of customer support ticket history was also taken, covering what customers had written in to report, what they had complained about, and what Charter's service agents had typed in response. Support ticket records are a particularly durable category of exposure: unlike a compromised password, the content of a support conversation cannot be reset.
ShinyHunters ran a private extortion period before surfacing publicly. Charter was added to the group's leak site with a May 27, 2026 ransom deadline. Charter disclosed the breach publicly on May 26, the day before the deadline expired, and only after the threat actor had already gone public. The company stated that no sensitive personal information or Customer Proprietary Network Information had been exfiltrated. ShinyHunters disputed that claim with screenshots within hours. For an organisation with more than 32 million customer relationships and significant regulatory obligations under Federal Communications Commission rules governing Customer Proprietary Network Information, the question of what was actually taken is now a matter for regulators as well as lawyers.
The defences that failed here were not weak by conventional standards. Charter's corporate identity infrastructure ran on Microsoft Entra, a market-leading enterprise identity platform. Salesforce is a hardened, enterprise-grade CRM environment. The Spectrum business processes represented by a customer database, service plan records, and support ticket history sit behind a credential layer that is, in normal operation, adequate. The failure was not at the perimeter. The failure was that once a legitimate credential existed, the Salesforce export that followed raised no flag and encountered no gate. A human being with a convincing voice on the telephone turned a technical control into a formality.
The specific point GoFirm protects is the execution boundary: the moment a high-consequence action is actually initiated. A Salesforce bulk export of 40 million customer records is an execution event. Before that export runs, a confirmation request goes to the named data owner or authorised system administrator on their registered device, requiring biometric confirmation. If no confirmation is received, the export does not execute. The attacker, holding a harvested credential, cannot produce biometric confirmation on the real authority's registered device via a separate out-of-band channel. The authentication step the attacker cleared was the identity layer. The execution layer, where the consequential action actually happens, would have remained closed.
The same logic applies wherever access to a sensitive system constitutes an execution event in its own right. Where the access event itself triggers consequential action, GoFirm places the confirmation requirement at that point. The attacker cannot be told they need to confirm on a device they do not hold, in a channel they cannot intercept. A vishing caller who has obtained a valid credential cannot produce that confirmation. The execution boundary holds regardless of how credible the impersonation appears.
GoFirm is The Authority Platform. Stop unauthorised action. Every time.
In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence. Osinto's AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in seconds, not days.
References
1. TechRadar (Sead Fadilpasic), "Charter Communications confirms data breach - ShinyHunters blamed after threat to leak user info online", 27 May 2026. https://www.techradar.com/pro/security/charter-communications-confirms-data-breach-shinyhunters-blamed-after-threat-to-leak-user-info-online
2. GBlock, "One Vishing Call Cost Charter 40 Million Customer Records", 28 May 2026. https://www.gblock.app/articles/charter-ters-blamed-a40m-salesforce-vishing-breach-may-2026
3. eSecurity Planet, "ShinyHunters Alleges 42M Records Stolen from Charter Communications". https://www.esecurityplanet.com/threats/ters-blamed-aalleges-42m-records-stolen-from-charter-communications/
