Charter confirmed a 2026 breach of the Salesforce customer database behind Spectrum, after attackers voice-phished an employee's Microsoft Entra login around April 1. No Social Security or payment data was reported taken, but names, addresses, emails, phone numbers, plan details, and support tickets leaked — which makes convincing fake "Spectrum support" calls the real threat.
What Happened in the Charter Spectrum Data Breach?
The intrusion followed the same playbook used against dozens of large companies in the 2025–2026 Salesforce social-engineering wave:
- Around April 1, 2026: an attacker linked to the ShinyHunters extortion group called a Charter employee and talked them out of Microsoft Entra (Azure Active Directory) credentials — a vishing attack, not malware.
- With that access, the attacker pivoted into Charter's Salesforce CRM environment and exfiltrated customer and employee records.
- May 26, 2026: Charter disclosed the intrusion publicly — roughly eight weeks after the initial phone call.
- ShinyHunters listed Charter on its leak site and claimed 40 to 42 million records. Independent analysis of the published dataset tied it to roughly 13 million individuals, including about 4.9 million unique email addresses and around 27,000 employee records.
- Charter's position is that no sensitive personal information or customer proprietary network information (CPNI) was exfiltrated.
What Data Was Exposed?
Researchers reviewing the leaked dataset reported the following fields, weighted heavily toward Spectrum Enterprise and business accounts but including residential contacts:
- Full names
- Email addresses (work and personal)
- Physical addresses, including home addresses
- Phone numbers
- Account and plan information
- Customer support ticket records — nearly 10 million of them, including the free-text notes agents wrote
The Support Tickets Are the Dangerous Part
A leaked email address is a nuisance. A leaked support ticket is a script. It tells a caller which outage you complained about, what equipment is in your house, which promotion you argued over, and what your account status is. Someone who opens with "I'm calling about the modem swap on your ticket from March" does not sound like a scammer — and that is exactly how account takeovers and refund scams start.
Are You Affected?
If you were a Spectrum residential or business customer in early 2026, assume your contact record was in the CRM. Charter has said it is notifying affected customers; watch your email and physical mail for a notice. You can also check whether your email address appears in known breach corpora using a reputable breach-lookup service. Because the dataset skews toward Spectrum Enterprise, business and account-administrator contacts should treat themselves as high priority.
Step 1: Assume the Next "Spectrum" Call Is Fake
Adopt one rule and never break it: you do not give information to inbound callers. If someone claiming to be Spectrum calls, hang up and dial the number printed on your bill or in the official app. The same applies to texts about billing failures and emails about "account verification." Never read back a one-time code — no legitimate agent will ever ask for one.
Step 2: Set an Account PIN or Passcode
Log into your Spectrum account and add a security PIN or passcode required for account changes and support interactions, if you do not already have one. This is the single control that stops a caller armed with your leaked ticket history from making changes on your account.
Is your data already out there?
Leaked data ends up on broker sites and in scammers' hands. Run a free 60-second scan to see your exposure — then let us remove it.
Run a free scan★★★★★ 4.8/5 · Trusted by thousands of families
Step 3: Move Two-Factor Authentication Off SMS
Leaked phone numbers feed SIM-swap and port-out fraud, which turns your SMS codes into the attacker's codes. Switch your email, banking, and any account tied to that number to an authenticator app or a passkey. Separately, call your mobile carrier and add a port-out PIN or a number-transfer lock.
Step 4: Watch for Refund and Discount Scams
The most common Spectrum-themed fraud right now is an offer: a billing credit, a loyalty discount, a refund for the outage in your ticket. The caller asks you to confirm your account, then to authorize a small payment or install a "verification" app. Both are theft. Any real credit will appear on your bill without a phone call.
Step 5: Freeze Your Credit Anyway
No SSNs were reported in this dataset, so new-account fraud is not the primary risk here — but a freeze is free, takes about 15 minutes at Equifax, Experian, and TransUnion, and protects you from every other breach your data sits in. Given the volume of 2026 incidents, there is no good reason to leave your credit unfrozen.
Is There a Lawsuit?
Yes. A proposed class action was filed on June 1, 2026 in Connecticut federal court (Kent v. Charter Communications, No. 3:26-cv-00850, D. Conn.), and at least four federal complaints were on file by August 2026. Litigation is in an early stage with no settlement or timeline. If you want to preserve a claim, keep your breach notice, document any fraud, and log time spent on calls and remediation.
Step 6: Remove the Public Half of Your Profile
What makes leaked contact data usable is corroboration. A scammer who can pair your Spectrum ticket with your current address, relatives' names, and prior addresses — all published free on people-search sites — sounds credible enough to get past you. Removing that public layer is the part of your exposure you can actually control after a breach.
PrivacyOn removes your data from 100+ data brokers and people-search sites, re-checks them continuously because brokers relist, and adds dark web monitoring so you hear when your details show up in a new dump. Plans start at $8.33/month, cover up to 5 family members, and a free exposure scan shows what is public about you right now.
Frequently Asked Questions
Did Charter confirm the Spectrum data breach?
Yes. Charter publicly disclosed the intrusion on May 26, 2026 and has said it is notifying affected customers, while maintaining that no sensitive personal information or CPNI was exfiltrated. The attacker group publicly claimed a far larger haul than Charter acknowledges.
How many Spectrum customers were affected?
The numbers are disputed. ShinyHunters claimed 40–42 million records; independent analysis of the leaked dataset tied it to roughly 13 million individuals, including about 4.9 million unique email addresses and around 27,000 employee records. Charter has not published a confirmed individual count.
Was my Social Security number or credit card exposed?
No SSNs or payment card numbers have been reported in the leaked dataset, and Charter says no sensitive personal information was taken. The exposed fields are names, addresses, emails, phone numbers, plan details, and support ticket contents — which is why targeted phishing and vishing are the main risks.
How did hackers get into Charter's systems?
Through a person, not a vulnerability. An attacker phoned an employee and social-engineered their Microsoft Entra credentials around April 1, 2026, then used that access to reach Charter's Salesforce CRM. It is the same technique used across the broader 2025–2026 Salesforce breach wave.
What should I do first if I was a Spectrum customer?
Add a PIN or passcode to your Spectrum account, stop giving information to inbound callers, and move SMS-based two-factor authentication to an authenticator app or passkey. Then freeze your credit and clean up the public data that makes impersonation calls believable.
How do I stop scammers from using my leaked contact details?
You cannot recall the leak, but you can remove the public records that make it convincing — your address history, phone numbers, relatives, and employer on people-search sites. PrivacyOn removes them across 100+ brokers with ongoing monitoring and dark web alerts, from $8.33/month.