HebridesCyber
← back to Security Weekly

Charter Communications: Tens of Millions of Records Stolen and Published — What Extortion-Only Attacks Mean for You

13 July 2026·1 min read

No ransomware, no encryption — just theft and a public leak site. Charter's May 2026 breach shows attackers increasingly skip encryption entirely.

What happened

In May 2026, an extortion group stole data from Charter Communications — reporting put the stolen records at over 42 million and the number of affected individuals at close to 5 million — and published it on a leak site rather than deploying ransomware to encrypt Charter's systems.

The shift worth noticing

Classic ransomware follows a familiar shape: encrypt the victim's files, demand payment for the decryption key, and backups are your main defence. A growing number of attacks now skip the encryption step entirely. The attacker copies the data and threatens to publish it unless paid — "extortion-only." Your backups don't help here, because nothing was ever locked; the threat is exposure, not downtime.

What actually reduces exposure to this specific threat

  • Data minimisation. The single most effective defence against a leak is not holding data you don't need. Old customer records, historic form submissions, and abandoned databases are pure liability with no upside.
  • Encryption at rest. If data is stolen but unreadable without a key attackers don't have, the leak threat loses most of its teeth.
  • Export/access logging. A sudden bulk export of a customer table is detectable if something is watching for it — most small business setups don't log this at all.
  • Know what you'd say. Extortion-only incidents move fast once the leak site goes up; having a basic incident response plan (who do you tell, in what order, by when) matters more than people expect.

Source: roundup reporting via TechCrunch

$ ./get-your-score

Get a free Security Score for your site

Automated TLS, headers, DNS, and exposure checks — results in under a minute.

Request a free scan