Latest / Tech Talks With Kinsoft / Charter/Spectrum – ShinyHunters Vishing Breach
Transcript
- 0:00Welcome to Tech Talks with Kinsoft. Hey, everyone.
- 0:02So picture a massive corporate data breach for
- 0:06a second. You know, you're probably imagining
- 0:08elite hackers sitting in a dark room somewhere,
- 0:11right? Frantically typing complex code to like
- 0:15smash through sophisticated firewalls. Oh, yeah.
- 0:19The classic guy in a hoodie in a basement trope.
- 0:21Exactly. We'll delete that image entirely. Because
- 0:24today we are looking at how a really simple phone
- 0:28call, just a smooth talking voice on the line,
- 0:31unraveled one of the biggest telecom networks
- 0:34in America. It really is wild when you break
- 0:36it down. Yeah, it is. And, you know, we designed
- 0:39this show with a very specific premise in mind
- 0:41to tackle stories just like this one. We take
- 0:44a stack of reputable sources like articles, research
- 0:46papers, our own notes, and we just extract the
- 0:49most important insights. Right. So you can stay
- 0:51perfectly informed without succumbing to the
- 0:54whole information overload thing because. I mean,
- 0:57there is just a relentless flood of data out
- 0:59there right now. Oh, absolutely. And our entire
- 1:00job is to find the signal through all that noise,
- 1:03especially when the security of your personal
- 1:05data is on the line. Which brings us to today's
- 1:08mission. We are unpacking an event that perfectly
- 1:10illustrates why paying attention to those signals
- 1:12is so crucial. We're digging into the massive
- 1:16Charter Communications data breach. Right. Which
- 1:19most of you listening probably know better by
- 1:21their primary consumer brand, Spectrum. Yeah,
- 1:24exactly. Spectrum. And this breach was officially
- 1:27confirmed in late May of 2026. Now, before we
- 1:32really get into the weeds here, I just want to
- 1:33clarify that our entire analysis today is based
- 1:36strictly on reporting from two excellent sources.
- 1:39That's Ticklicious. and security affairs. Both
- 1:42really solid sources for this kind of thing.
- 1:44Yeah, definitely. And the hook here, I mean,
- 1:46the reason the story is just so fascinating is
- 1:48that there was no malware involved in the initial
- 1:51break -in at all. No zero -day software exploit.
- 1:54Nothing like that. Right. To really grasp the
- 1:56sheer scale of the damage here, we first have
- 1:58to look at the honestly incredibly mundane way
- 2:01the attackers actually got inside the network.
- 2:03Yeah, it completely flips the traditional cybersecurity
- 2:05narrative on its head. It really does. I mean,
- 2:08we spend so much time and money focusing on hardening
- 2:12the software and the hardware, right, that we
- 2:14just, we often forget about the wetware, the
- 2:17human element. The human element, yeah. So let's
- 2:19lay out the timeline. The initial entry happened
- 2:21on April 1st, 2026. April Fool's Day. Yeah, which
- 2:26is just dark irony. Anyway, this extortion group
- 2:29known as Shiny Hunters used a technique called
- 2:32voice phishing. or vishing, to compromise a charter
- 2:35employee. Basically, they got an employee on
- 2:38the phone and just, well, talked them into surrendering
- 2:40their Microsoft Enter access credential. No brute
- 2:42force password cracking, just a converse date.
- 2:45Okay, let's unpack this. Because think about
- 2:48it this way. Imagine a bank spending tens of
- 2:51millions of dollars building a state -of -the
- 2:53-art high -tech vault. Right. You have biometric
- 2:55scanners, laser grids, you know, foot -thick
- 2:58steel doors. And then... A con artist just calls
- 3:01this security guard working the front desk, speaks
- 3:03a highly convincing story, and just asks for
- 3:06the keys. And the guard just hands them over.
- 3:08Exactly. They just hand them over. What's fascinating
- 3:10here is the psychology behind a vishing attack,
- 3:13because that's what makes it so devastating.
- 3:15It entirely bypasses all those expensive technical
- 3:18barriers you just mentioned simply by exploiting
- 3:21basic human nature. Right. Like our desire to
- 3:24be helpful. Exactly. Human trust and our inherent
- 3:26desire to be helpful in a crisis. The attacker
- 3:29isn't fighting a complex algorithm. You know,
- 3:32they are manipulating a person. So they usually
- 3:35create this highly believable sense of urgency.
- 3:39Like what? Well, they might pretend to be from
- 3:42the IT help desk, right? Saying there's an emergency
- 3:45with the employee's payroll account and they
- 3:48need to verify a login code immediately. Oh,
- 3:51wow. And that's how they get around two -factor
- 3:53authentication, isn't it? Because, I mean, we
- 3:55are always told that two -factor authentication
- 3:57is the silver bullet. Yeah, the holy grail of
- 3:59basic security. Right. But if the IT guy on the
- 4:02phone says, you know, hey, I just texted you
- 4:04a six -digit code to verify your identity. Could
- 4:07you just read it back to me? Well, you just gave
- 4:08the attacker your second factor. Precisely. A
- 4:11text message code is completely useless as a
- 4:14defense if the human holding the phone simply
- 4:16reads it aloud to the person trying to break
- 4:18in. Man. Yeah. When an attacker creates that
- 4:21artificial pressure, critical thinking just shuts
- 4:24down. And we have to look closely at what they
- 4:26were actually targeting here, too, because they
- 4:28weren't just asking for access to the employee's
- 4:30email. Right. They specifically targeted Microsoft
- 4:32Entra credentials. Now, my understanding is that
- 4:35Microsoft Entra isn't just like a standard login.
- 4:39It's essentially. the master key card a hotel
- 4:43manager uses. Oh, that's a perfect analogy. Yeah,
- 4:46like you get that one card and suddenly you can
- 4:48walk into any room in the building without picking
- 4:49a single lock. Exactly. Untra is a centralized
- 4:53identity and access management system. It's basically
- 4:56the modern evolution of Azure Active Directory.
- 4:58So in a corporate environment, it acts as the
- 5:01master key. So it proves who you are to all the
- 5:03other apps. Right. It's the central authority
- 5:05that proves who you are, and then it automatically
- 5:08grants you access to all the different software
- 5:10applications you need to do your job. So by stealing
- 5:14those specific credentials, the attackers gain
- 5:17the ability to impersonate that employee across
- 5:19the entire corporate ecosystem. Wow. Yeah. For
- 5:23a modern threat actor, an identity system like
- 5:25Microsoft Entra is the absolute holy grail. Okay,
- 5:29so they have the master key, but an identity
- 5:33platform like Entra doesn't actually hold the
- 5:35company's customer data, right? Yeah. It just
- 5:38points you to it. Correct. It's the gateway.
- 5:40So where did this stolen key card actually take
- 5:42them? And I guess that brings us to the next
- 5:44phase of this event. The loot and the massive
- 5:48dispute over what was actually inside that vault.
- 5:50Oh, yeah. The dispute is fascinating. Because
- 5:52once Shiny Hunters had the Entra account, it
- 5:55led them directly into the company's Salesforce
- 5:57instance. And, you know, for anyone unfamiliar,
- 5:59Salesforce is a massive customer relationship
- 6:01management platform. It's basically the digital
- 6:03brain where a company stores its customer data,
- 6:06interactions, and support histories. Right. And
- 6:08this is where the reporting gets very muddy because
- 6:11we have two completely conflicting narratives
- 6:14about what was extracted from that database.
- 6:16Yeah. So let's lay out the claims. impartially
- 6:19based on the sources. On one side, we have the
- 6:22attackers. Shiny Hunters claims they exported
- 6:25a staggering 42 million records. That's a massive
- 6:29number. It's huge. And they claim this haul includes
- 6:32highly sensitive customer proprietary network
- 6:35information, or CP &I, which is federally protected
- 6:38telecom data. It reveals who you call. when you
- 6:42call them and exactly how long you speak. Right.
- 6:44And then on the other side, you have the company's
- 6:47official stance. Charter has explicitly denied
- 6:50that any sensitive personal information or PI
- 6:52or any CPI data was exfiltrated by the threat
- 6:55actor. So they're just flat out denying it. Yeah.
- 6:57They are flatly stating that the most serious
- 6:59part of the attacker's claim is false. Wait,
- 7:01hold on a second. Stop right there. Forty two
- 7:03million records. That math just doesn't work
- 7:05out. I mean, I'm looking at the notes here and
- 7:07Charter only has about 32 million U .S. customers
- 7:10in total. Right. Are the attackers just entirely
- 7:13fabricating this number? How can they steal more
- 7:16records than the company has customers? Well,
- 7:18on the surface, it definitely. looks like an
- 7:20outright lie. And look, it is a very common tactic
- 7:23for extortion groups to inflate their numbers,
- 7:26right? Just to increase the media pressure on
- 7:29the victim. Sure. Make it sounds barrier than
- 7:31it is. Exactly. However, when you understand
- 7:33how a Salesforce database operates, the number
- 7:36actually starts to make. a weird kind of sense
- 7:40really because it likely contains a massive amount
- 7:43of duplicated data and more importantly a crm
- 7:46database doesn't just hold current active paying
- 7:49customers oh i see where you're going with this
- 7:51yeah it holds data on former customers who cancelled
- 7:54years ago and crucially it holds data on prospective
- 7:57customers you know people who simply called to
- 8:00inquire about internet service or maybe filled
- 8:02out a form online but never actually signed up
- 8:04right so the total number of profile records
- 8:07in a sales system will naturally be significantly
- 8:09higher than the current active subscriber count.
- 8:12OK, that makes sense. They are scooping up the
- 8:14leads, not just the active accounts. But I want
- 8:17to circle back to the CP &I data. The call logs.
- 8:20Yeah, that's the scary part. Even with Charter
- 8:23denying that this specific data was taken, we
- 8:26need to understand why shiny hunters would even
- 8:28brag about taking it. Like, why is CPI so uniquely
- 8:32dangerous if it falls into the wrong hands? It's
- 8:34vital to understand this because CPI reveals
- 8:37the invisible network of your life. It isn't
- 8:40just about knowing your phone number or your
- 8:42billing address. Right. If someone possesses
- 8:44your call logs, they know if you are making recurring
- 8:47calls to a bankruptcy lawyer, maybe a divorce
- 8:50attorney, an oncologist, a suicide hotline, or
- 8:53a substance abuse treatment center. Oh, wow.
- 8:55Yeah. They know exactly when you called and how
- 8:57long you stayed on the line. You know, when you
- 8:59frame it like that, the metadata is almost more
- 9:02invasive than recording the actual phone call.
- 9:05I mean, you don't need to hear a single word
- 9:07of the conversation if you know a person is talking
- 9:09to a cardiologist for an hour every Tuesday afternoon.
- 9:12The story just writes itself. Exactly. It strips
- 9:14away your privacy without the attacker ever needing
- 9:17to intercept the actual content of your communications.
- 9:20And that is exactly why it's protected by strict
- 9:22federal laws and why the stakes in this specific
- 9:25dispute between Charter and Shiny Hunters are
- 9:28incredibly high. Well, we do have some independent
- 9:30data to help us piece together what actually
- 9:32happened. The research team at CyberNews and
- 9:36the Breach Notification Service have at Ben Pound
- 9:38actually analyzed the data that shiny hunters
- 9:41leaked on the open web. Right, which they leaked
- 9:44when Charter apparently refused to pay their
- 9:46ransom. Yeah, exactly. And they indicate that
- 9:48roughly 4 .9 million unique email addresses were
- 9:51exposed. And this came along with names, physical
- 9:55addresses, phone numbers, and details from nearly
- 9:5710 million customer support tickets. That's a
- 10:00huge amount of support data. It is. They also
- 10:02found around 85 ,000 employee directory records,
- 10:05work emails, job titles, and some home addresses.
- 10:08The exposed systems seem to primarily manage
- 10:11current, former, and prospective business customers,
- 10:14basically the Spectrum Enterprise division. Look,
- 10:16that 4 .9 million figure is still a massive exposure,
- 10:20even if it falls way short of the 42 million
- 10:23they originally claimed. And honestly, it leads
- 10:26us to a much broader issue here. Right. Because
- 10:29this breach at Charter is alarming on its own,
- 10:31but we really have to zoom out to understand
- 10:34the current threat landscape. This was not an
- 10:36isolated random attack by some lone wolf. No,
- 10:39not at all. It's part of a highly successful,
- 10:42repeatable playbook being executed across the
- 10:44corporate world right now. now. Shiny Hunters
- 10:47is a well -known entity in the cybercriminal
- 10:50ecosystem. Definitely. And the sources note they're
- 10:52associated with a broader, loosely connected
- 10:54network that researchers refer to as the Calm.
- 10:57Which, honestly, sounds incredibly ominous. It
- 11:00really does sound like a movie villain organization.
- 11:02But what makes the comm unique and uniquely dangerous
- 11:05is their demographic makeup. How so? Well, this
- 11:08network is largely comprised of young, native,
- 11:11English -speaking threat actors based in Western
- 11:13countries. And that completely changes the dynamic
- 11:15of a vishing attack. Oh, right, because of the
- 11:18phone calls. Exactly. In the past, if a foreign
- 11:21threat actor tried to call an American corporate
- 11:23employee, the language barrier, maybe a thick
- 11:25accent or just awkward phrasing, would often
- 11:28be an immediate dead giveaway. The alarm bells
- 11:31would just ring in the employee's head. But when
- 11:33the person on the other end of the line sounds
- 11:35exactly like, you know, a frantic 22 year old
- 11:38I .T. intern from the Omaha office who just spilled
- 11:41coffee on the server. the employee's defenses
- 11:43drop completely. Exactly. The social engineering
- 11:46just becomes flawless. And this group has perfected
- 11:49a very specific, devastatingly effective playbook
- 11:52for 2026. Okay, let's break down the mechanics
- 11:55of that playbook because it operates like a corporate
- 11:57nightmare assembly line. Right. Step one is the
- 12:00vishing call. They socially engineer an employee
- 12:03into handing over credentials and bypassing MFA.
- 12:06Right. Step two is compromising the single sign
- 12:08-on, or SSO, accounts. These are systems like
- 12:11Microsoft Entra, Okta, or Google Workspace. Step
- 12:14three is the pivot. And that's where the damage
- 12:16scales up. Yeah. Once they have that SSO token,
- 12:19that Hotel Master keycard we talked about, they
- 12:22jump into all connected SaaS platforms. They're
- 12:24instantly inside Salesforce, Slack, Microsoft
- 12:27365, Zendesk. And finally, step four. They extract
- 12:32data at massive scale and demand a cryptocurrency
- 12:35ransom. Yeah. And if the victim refuses to pay
- 12:38the ransom, the group just dumps the data on
- 12:40public leak sites. This destroys the company's
- 12:43reputation and forces future victims to take
- 12:45their extortion threats seriously. It's a brutal
- 12:48cycle. It is. And the sources list an absolutely
- 12:51staggering string of victims in 2026 alone that
- 12:54fell for this exact playbook. I mean, Panera
- 12:56had over 5 million customers breached. Instructure's
- 13:00Canvas platform, which is used by more than 30
- 13:02million students and teachers globally, was breached.
- 13:04The identity protection company Aura saw nearly
- 13:071 million customers breached. And the security
- 13:09firm ADT had 5 .5 million customers breached.
- 13:13Just massive numbers across the board. Yeah.
- 13:15And here's where it gets really interesting.
- 13:17And I have to ask you about the underlying technology
- 13:19here. Because for years, the IT industry has
- 13:22been preaching that single sign -on is the absolute
- 13:25pinnacle of corporate security oh absolutely
- 13:27it's been the gold standard right you have one
- 13:29strong password secured with multi -factor authentication
- 13:32and it safely connects your entire workflow but
- 13:36if one stolen password given away over a simple
- 13:39phone call unlock Salesforce slack your email
- 13:43and your customer databases aren't we just putting
- 13:46all our highly sensitive eggs in one incredibly
- 13:49vulnerable basket. You are hitting on the central
- 13:52debate in modern identity architecture right
- 13:55there because single sign -on is fundamentally
- 13:57a double -edged sword. On the positive side,
- 14:00you have usability and administrative control.
- 14:02It is vastly more secure than forcing an employee
- 14:05to memorize 50 different complex passwords for
- 14:0750 different applications. Yeah, because when
- 14:10you do that, human nature takes over and they
- 14:13just write all 50 passwords on a sticky note
- 14:15attached to their monitor. Right. The classic
- 14:17analog security flaw just defeats the digital
- 14:20security. So SSO allows security teams to enforce
- 14:25strict logging policies at a single choke point.
- 14:28But the other edge of that sword. Is the blast
- 14:30radius. Centralized access inherently means centralized
- 14:33risk. The architecture basically works using
- 14:37authentication tokens. So when you log into UNTRA,
- 14:40it generates a digital wristband that tells Salesforce,
- 14:43hey, I vetted this person, let them in. Oh, I
- 14:45see. If the human element fails, like if an employee
- 14:49is successfully vished and hands over that token,
- 14:51the resulting blast radius is catastrophic. The
- 14:55attacker doesn't just breach one application.
- 14:57They get the keys to the entire digital kingdom.
- 15:00Man. Yeah. The exact same architecture that makes
- 15:03it seamless for an employee to do their daily
- 15:05job makes it utterly seamless for an attacker
- 15:08to pivot and steal millions of records in an
- 15:10afternoon. Wow. Well, we have spent a lot of
- 15:12time talking about the macro level here. You
- 15:14know, the corporate networks, the criminal syndicates,
- 15:16the architecture of single sign -on. But let's
- 15:18bring this right into the listener's living room.
- 15:20Good idea. If you are a Spectrum customer sitting
- 15:23at home right now, hearing that an attacker might
- 15:25have your contact info and your support ticket
- 15:28history, that changes everything. You aren't
- 15:31just a generic number in a database anymore.
- 15:33You're a target. Exactly. So with all this data
- 15:36floating around the open web, what is the actual
- 15:39defense plan? Well, it requires an immediate
- 15:41proactive shift in how you protect your identity.
- 15:44Because even if Charter's claim is true and the
- 15:46highly sensitive CP &I data wasn't taken, the
- 15:49data that is confirmed to be out there is bad
- 15:51enough. Yeah. Your name, address, email. Right.
- 15:54Your physical address, your phone number, your
- 15:56email. That is more than enough ammunition for
- 15:59a secondary wave of attacks. So let's outline
- 16:01the actionable steps directly from the reporting.
- 16:03If you are a Spectrum customer, the very first
- 16:06thing you need to do is log in and change your
- 16:08Spectrum account password. Simple but essential.
- 16:11Yeah. Second, turn on two -factor authentication
- 16:13for your account if you haven't already. Third,
- 16:15go to the website haveibnpeln .com and type in
- 16:19your email to verify if your specific address
- 16:21was part of the $4 .9 million swept up in this
- 16:23breach. Right. Highly recommend that site. And
- 16:26finally, the big one. You need to place a credit
- 16:28freeze at all three major credit bureaus. That's
- 16:32Equifax, Experian, and TransUnion. I really want
- 16:35to spend a moment on the credit freeze, actually,
- 16:37because it is arguably the most powerful tool
- 16:40you have to prevent identity theft. It's entirely
- 16:43free and it is easily reversible when you need
- 16:46to apply for a loan. How does it actually work
- 16:48in practice? Well, what a freeze actually does
- 16:51is lock your credit report at the database level.
- 16:54So if an attacker tries to use your leaked name
- 16:56and physical address to open a new credit card
- 16:59in your name, the bank will automatically query
- 17:02Experian or Equifax to check your credit score.
- 17:05But because of the freeze, the bureau denies
- 17:07the bank access to the file. And without seeing
- 17:10the credit file, the bank automatically blocks
- 17:12the fraudulent application. It just shuts the
- 17:14attacker down right at the source. That is brilliant.
- 17:17It stops the attack entirely. It does. But there
- 17:21is another layer to this defense plan that requires
- 17:24a shift in your daily behavior, I think, because
- 17:27think about the root cause of this entire corporate
- 17:30breach. If a highly trained employee working
- 17:33inside a massive telecommunications company can
- 17:35be tricked over the phone by a confident. Fast
- 17:38talking voice. You have to be incredibly skeptical
- 17:41of anyone calling you claiming to be from Spectrum
- 17:44Support. Oh, absolutely. And that is where the
- 17:46leakage of nearly 10 million customer support
- 17:49tickets becomes so incredibly dangerous. Right.
- 17:52Because of what they know. Yeah. We aren't dealing
- 17:54with generic automated spam calls here. We are
- 17:57looking at highly targeted spear phishing and
- 17:59account takeover attempts. Because the hackers
- 18:01possess your support history, they know exactly
- 18:04what you have been struggling with. That's terrifying.
- 18:07They know if you called three weeks ago complaining
- 18:09about a slow router or maybe disputing a weird
- 18:12charge on your bill. So the attacker doesn't
- 18:14just blindly call and say, hi, this is Spectrum.
- 18:16They call and say, you know, hi, this is Dave
- 18:18from Spectrum Advanced Support. I am following
- 18:20up on that ticket you opened on May 12th. regarding
- 18:23the slow upload speeds on your living room router,
- 18:26are you still experiencing that lag? And just
- 18:30like that, the fake call becomes incredibly convincing.
- 18:34It instantly lowers your guard. The attacker
- 18:36builds rapport and trust because they possess
- 18:39inside information that only the real company
- 18:41should have. And then they strike. Right. Once
- 18:44they establish that trust, they spring the trap.
- 18:46They might ask you to confirm your account details
- 18:48or read back a security code they just texted
- 18:50you to, quote, verify your identity or even click
- 18:53a link in an email to authorize a diagnostic
- 18:55scan. In reality, they are using that code or
- 18:59that link to take over your personal account
- 19:01entirely. It is terrifyingly clever. So the golden
- 19:05rule moving forward really has to be if you receive
- 19:08an inbound call, even if the person on the other
- 19:10end knows your entire support history, you just
- 19:13politely hang up. Exactly. Just hang up. You
- 19:16look up the official support number for Spectrum
- 19:18yourself and you dial them directly. Never, ever.
- 19:22Trust the inbound caller ID. Precisely. You must
- 19:25always verify the communication channel by initiating
- 19:27it yourself. I think it really highlights how
- 19:30the true front lines of cybersecurity have moved.
- 19:32They aren't just at the corporate firewalls and
- 19:35network routers anymore. The front lines are
- 19:37on our own smartphones, relying on our own judgment.
- 19:40Which brings us to a lingering thought that I
- 19:43think everyone needs to grapple with after unpacking
- 19:45a story like this. We are watching massive corporations
- 19:48spend billions of dollars on advanced artificial
- 19:50intelligence, machine learning anomaly detection,
- 19:53state -of -the -art firewalls. Billions. Yeah.
- 19:57But as these technical defenses become nearly
- 19:59impenetrable, is the ultimate unpatchable vulnerability
- 20:03of the future simply a confident, persuasive
- 20:05human voice on the other end of a phone line?
- 20:08Well, as long as humans operate the systems,
- 20:10human psychology will remain the most exploitable
- 20:12attack vector. We can build the most advanced
- 20:14digital vaults in the world, but we still have
- 20:16to ensure the people guarding them know how to
- 20:18spot a con. That is a chilling thought to end
- 20:21on, but an absolutely necessary one. And look,
- 20:24if exploring the mechanics of this breach made
- 20:26you rethink your own business's defenses, or
- 20:29if you find yourself wondering how resilient
- 20:30your team really is against these kinds of modern
- 20:33social engineering tactics, you should visit
- 20:35www .kinsoft .com .au to discuss your security
- 20:40and IT needs. Yeah, they have the expertise to
- 20:43help you build not just robust technical defenses,
- 20:45but really strong human defenses as well. Well,
- 20:48that brings us to the end of our time today.
- 20:49Thank you so much for joining us and trusting
- 20:51us to help you navigate the noise. Stay skeptical,
- 20:54stay secure, and we will catch you next time
- 20:56on Tech Talks with Kinsoft.