
ShinyHunters, an extortion group associated with voice phishing and rapid data exfiltration, published alleged stolen data from Charter Communications on a Tor-based leak portal. The portal listing suggests Charter did not pay a ransom to prevent publication. The group claimed the dataset includes more than 42 million customer records and customer proprietary network information (CPNI). A breach notification analysis indicates 4.9 million unique email addresses with names, addresses, and phone numbers, plus 85,000 employee-related records containing job titles. Charter stated it followed security protocols, worked with authorities, and reported that only sales tools used for managing business customers were impacted, with no CPNI or sensitive personal information released.
"ShinyHunters is known for engaging in voice phishing attacks to gain access to victim organizations' networks and rapidly exfiltrate data that it then threatens to leak online unless a ransom is paid. The group lists its victims on a Tor-based leak site, and the data it claims to have been stolen from Charter was made available for download on that portal on Thursday, which suggests that the company did not pay a ransom to prevent its publication."
"According to ShinyHunters' post, the stolen data includes over 42 million customer records, along with customer proprietary network information (CPNI). The number of potentially affected individuals, however, appears to be only 4.9 million, data breach notification website HaveIBeenPwned says. Its analysis of the data revealed 4.9 million unique email addresses, along with names, addresses, and phone numbers."
"The data contains 85,000 records associated with employee accounts, each of which includes a job title. Over the past year, ShinyHunters has claimed numerous high-profile data breaches, mainly involving Salesforce customers. Some of these include Canvas, CarGurus, Carnival, Panera Bread, 7-Eleven, and Grafana."
""We are aware of the situation, following our security protocols, and are working with appropriate authorities. Only sales tools used to manage current, past, and prospective business customers were impacted; no CPNI or sensitive PI was released by the threat actor," a Charter spokesperson said, responding to a SecurityWeek inquiry."
Read at SecurityWeek
Unable to calculate read time
Collection
[
|
...
]