ShinyHunters allegedly gained access to Spectrum/Charter Communications' Salesforce environment by vishing an employee and compromising the employee's Microsoft Entra account. The actors reportedly used legitimate SSO access and native Salesforce capabilities to export customer data at scale, without exploiting a software vulnerability, deploying malware, or escalating privileges. Charter disclosed the incident on May 26, 2025, and said sensitive personal information and customer proprietary network information (CPNI) were not taken; ShinyHunters disputed that assertion and began releasing purported data samples the following day.
The intrusion reflects the social-engineering and identity-centric tradecraft associated with the Scattered LAPSUS$ Hunters ecosystem, an alliance linked to Scattered Spider, LAPSUS$, and ShinyHunters activity. Organizations using Entra and Salesforce should prioritize resistant help-desk identity-verification processes, Conditional Access, monitoring of Entra sign-ins and Salesforce activity, behavioral detection, and controls that restrict anomalous or bulk data exports.

Get the infrastructure and lures behind it.
5 events from the most recent confirmed update back to the earliest known activity.
The FBI issued a public warning urging organizations to verify urgent or unusual requests through an alternative communications channel, a precaution relevant to the voice-phishing tactics described in the Charter incident.
Have I Been Pwned added the Charter incident to its breach database and confirmed exposure of email addresses, customer names, and an employee directory containing roughly 85,000 records.
After Charter did not enter negotiations following the group's ultimatum, ShinyHunters began publishing samples of allegedly stolen data. The group disputed Charter's assertion that no CPNI was taken, releasing screenshots it characterized as CPNI.
After Charter appeared on ShinyHunters' leak site, Charter publicly confirmed the incident. The company said sensitive personal information and Customer Proprietary Network Information (CPNI) had not been stolen.
ShinyHunters allegedly used voice phishing to obtain a Charter employee's Microsoft Entra credentials, then used legitimate SSO access to enter Spectrum/Charter Salesforce and bulk-export customer records. The described intrusion did not involve exploitation of a vulnerability, malware deployment, privilege escalation, or lateral movement.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
3 references tracked. Mallory keeps watching after this page renders.
codeby.net
Open sourcesosransomware.com
Open sourcepushsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.