Charter Communications: Tens of Millions of Records Stolen and Published — What Extortion-Only Attacks Mean for You
No ransomware, no encryption — just theft and a public leak site. Charter's May 2026 breach shows attackers increasingly skip encryption entirely.
What happened
In May 2026, an extortion group stole data from Charter Communications — reporting put the stolen records at over 42 million and the number of affected individuals at close to 5 million — and published it on a leak site rather than deploying ransomware to encrypt Charter's systems.
The shift worth noticing
Classic ransomware follows a familiar shape: encrypt the victim's files, demand payment for the decryption key, and backups are your main defence. A growing number of attacks now skip the encryption step entirely. The attacker copies the data and threatens to publish it unless paid — "extortion-only." Your backups don't help here, because nothing was ever locked; the threat is exposure, not downtime.
What actually reduces exposure to this specific threat
- Data minimisation. The single most effective defence against a leak is not holding data you don't need. Old customer records, historic form submissions, and abandoned databases are pure liability with no upside.
- Encryption at rest. If data is stolen but unreadable without a key attackers don't have, the leak threat loses most of its teeth.
- Export/access logging. A sudden bulk export of a customer table is detectable if something is watching for it — most small business setups don't log this at all.
- Know what you'd say. Extortion-only incidents move fast once the leak site goes up; having a basic incident response plan (who do you tell, in what order, by when) matters more than people expect.
Source: roundup reporting via TechCrunch
$ ./get-your-score
Get a free Security Score for your site
Automated TLS, headers, DNS, and exposure checks — results in under a minute.
Request a free scan