ShinyHunters Leaks Charter Communications Data, Potentially Impacting 5 Million Customers

2026-05-31T08:51:45Zc6cda94c9dbe7fec56f4df72e721c70dd7f5eeebf2f5002c4e89e80606d7937d
CVE-2026-35616ai-assisted-malwareandroid-malwareasocksbackup-keysbotnet-takedownbtmobcode-signing-abusedata-breachextortionforticlientfortinetfox-tempestgreyvibeincident-responsemalware-as-a-servicemicrosoft-dcuphishingratrussia-linked-aptshinyhunterssignalwindows-zero-dayszero-day

What happened

Multiple high-impact incidents reported: the ShinyHunters extortion group published data allegedly stolen from Charter Communications (potentially ~5M customers) and Carnival disclosed a breach affecting ~5.995M people after social-engineering of employee accounts. Active exploitation of a critical FortiClient EMS remote code execution flaw (CVE-2026-35616, CVSS 9.1) is being used to deploy malware. A Signal-targeted phishing campaign is harvesting backup recovery keys to decrypt users’ message histories. Dutch authorities dismantled a massive botnet of ~17 million devices linked to proxy-as-a

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
c6cda94c9dbe7fec56f4df72e721c70dd7f5eeebf2f5002c4e89e80606d7937d
Enrichment time
2026-05-31T08:51:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · ShinyHunters Leaks Charter Communications Data, Potentially Impacting 5 Million Customers · Baitaphish