Read the Charter Communications disclosure next to the Abbott file and the shape is identical: a call to a person with the authority to restore access, an identity provider account taken over, and then a connected business system holding far more than the account itself suggested.
The reported vector is a vishing call against an employee’s Microsoft Entra account, with access dating to around the start of April 2026. From there the operators reached customer data held in a linked CRM environment. Charter’s early figure was 4.9 million accounts. Subsequent reporting has put the affected total above thirteen million.
Why The CRM Keeps Appearing
In campaign after campaign this year, the identity provider is the door and the customer relationship platform is the room. That is not an accident of tooling. A CRM is designed for broad internal readability — support staff need to see accounts quickly — and it is usually integrated with single sign-on so nobody has to manage a second credential.
Both properties are deliberate. Together they mean that an ordinary support identity, obtained by telephone, reads like an ordinary support identity right up until the export volume becomes abnormal. Very few organisations alert on export volume.
We are grading this file medium rather than high. The vector is consistent across sources and matches an established pattern, but the affected population has moved substantially between disclosures and we cannot yet reconcile the 4.9 million and thirteen-million figures against a single authoritative statement.
Compiled from public reporting, listed below. Where account totals differ between disclosures we give both and say which is the company’s. We have not reviewed the exfiltrated records. Corrections: corrections@forensicpost.com.
- List of recent data breaches in 2026Bright Defense
- Data breach news — recent data breaches in 2026Breachsense