Three major companies confirmed data breaches within weeks of each other. Charter Communications. Carnival Cruise Lines. 7-Eleven. Together, those incidents exposed data on more than 46 million people.
One hacker group is responsible for all three.
If you are a Spectrum customer, a Carnival guest, or someone who once applied for a 7-Eleven franchise, your information is likely sitting in a criminal database right now. And the advice most news outlets will give you, go change your password, will not protect you from what comes next.
The Breaches, Plainly Stated
Charter Communications (Spectrum)
In April 2026, hackers tricked a Charter employee into handing over their Microsoft account credentials over the phone. Once inside, they pulled records from Charter’s Salesforce system. The breach exposed names, addresses, phone numbers, and email addresses for an estimated 13 to 40 million customers. Charter initially said no sensitive data was taken. The leaked files said otherwise.
Carnival Cruise Lines
Also in April 2026, attackers used social engineering to access a Carnival employee account. They walked out with records on nearly 6 million people, including names, dates of birth, addresses, phone numbers, email addresses, and government-issued ID numbers. Carnival began notifying victims on May 27, 2026 and is offering 24 months of free credit monitoring.
7-Eleven
On April 8, 2026, attackers got into 7-Eleven’s franchise application system through a misconfiguration in Salesforce’s guest user settings. They took records on 185,000 people, including names, addresses, dates of birth, Social Security numbers, and driver’s license numbers. When 7-Eleven declined to pay a $250,000 ransom, the files went public.
One Group. Hundreds of Victims.
All three breaches trace back to a group called ShinyHunters.
By March 2026, ShinyHunters told reporters they had breached between 300 and 400 organizations in a single campaign. Roughly 100 of those are high-profile targets. The group spent months scanning Salesforce environments for misconfigured settings, finding unlocked access points companies did not know existed.
The 7-Eleven attack alone produced a 9.4-gigabyte archive of stolen files. It went public after the company refused to pay.
How Common Is This?
More common than most people realize.
Over 1,000 publicly reported data breaches occurred in the United States in 2023 alone. The Identity Theft Resource Center has tracked a steady increase year over year. Researchers estimate billions of records containing names, emails, addresses, and passwords are already circulating on criminal forums.
Your data has likely been exposed before. The question is not whether it happened. The question is what an attacker does with it next.
How an Attacker Uses Your Data
Most news coverage skips this part. Here is what actually happens after a breach.
Aggregation. Criminals combine records from multiple breaches. A name and email from one breach gets matched with a phone number from another, a home address from a third, and a date of birth from a fourth. Within days, a detailed profile of you is assembled, often more complete than a standard background check.
Credential stuffing. If past breaches included your passwords, automated tools test those credentials across hundreds of websites at once. Even if you changed your password on the breached site, attackers are testing it against your bank, your email, your Amazon account, and your healthcare portal.
Phishing with real context. Generic phishing emails are easy to spot. A message addressing you by name, referencing your address, and mentioning the specific company you do business with is much harder to dismiss. Breach data makes fake emails look legitimate.
Account takeover through social engineering. With your name, address, date of birth, phone number, and last four of your Social Security number, an attacker calls your bank or your carrier and pretends to be you. They say they lost access to their account. They answer the security questions correctly, because the answers came from your stolen records. They request a SIM swap or a password reset. They now control your phone number and your accounts.
Identity theft. With enough data, attackers open new credit lines, file fraudulent tax returns, access medical records, or sell your complete profile to other criminal groups.
The Charter and Carnival breaches handed attackers names, addresses, phone numbers, and emails. Enough for phishing and account takeover. The 7-Eleven breach added Social Security numbers and driver’s licenses. Enough for full identity theft.
Why Changing Your Password Is the Wrong Advice
When a company tells you to change your password after a breach, they are protecting themselves legally. They are not addressing the actual risk.
The Charter, Carnival, and 7-Eleven breaches did not expose passwords. They exposed identity data. No amount of password rotation changes your date of birth, your home address, your phone number, or your Social Security number.
Password resets matter when passwords are stolen. These breaches did not steal passwords. They stole the information attackers use to bypass your passwords entirely.
There is a bigger problem with this advice. It creates false confidence. People change their password and feel like they handled it. The real problem, that your personal data is permanently in criminal hands, does not go away.
Breaches happen constantly. The average person has had their information exposed multiple times across multiple incidents. Treating each one as a one-time password problem ignores what is clearly a long-term, cumulative threat. The goal is not to undo what happened. The goal is to make your data harder to exploit.
What You Should Actually Do
Freeze your credit. A credit freeze stops anyone from opening new accounts in your name until you lift it. It costs nothing. Do it at all three bureaus: Equifax, Experian, and TransUnion. Also freeze at ChexSystems and the National Consumer Telecom and Utilities Exchange. This is the most effective single step after a breach exposing personal information.
Switch to multi-factor authentication using an app, not SMS. SMS-based codes are vulnerable to SIM swapping, which is exactly the attack your stolen data enables. Authenticator apps like Authy or Google Authenticator generate codes tied to your device, not your phone number. Use them wherever possible.
Expect phishing attempts with your real details. After a breach, watch for emails, texts, or calls using your name and account information. Legitimate companies do not ask for passwords or Social Security numbers over the phone. If someone calls with your information and asks you to confirm it, hang up and call the company back using a number from their official website.
Set up account alerts on your financial accounts. Most banks and credit cards support text or email alerts for transactions above a set amount. Turn them all on.
Accept the credit monitoring if it is offered. Carnival is offering 24 months of free credit monitoring through TransUnion. Take it. It does not prevent identity theft, but it surfaces problems faster.
Check Have I Been Pwned. Go to haveibeenpwned.com and enter your email address. It will show you which breaches your email appeared in. This gives you a picture of what data is already in circulation.
The Bigger Picture
ShinyHunters breached hundreds of organizations in one campaign by exploiting one type of misconfiguration. That tells you where the real vulnerability sits. It is not your password. It is the trust model companies build around your personal data and the systems they store it in.
As a customer, you did not choose to have your information stored in a misconfigured Salesforce environment. You did not choose to have your records combined with data from a dozen other breaches and sold on a criminal forum. You did not opt into this risk.
That is why the response has to go beyond “change your password.” That advice protects the company’s reputation. It does not protect you.
Freeze your credit. Use an authenticator app for two-factor login. Stay alert to phishing using your real details. Those three steps address the actual threat.
NexSecure Solutions helps small organizations reduce cyber risk through practical reviews, clear priorities, and senior cybersecurity guidance. Schedule a free discovery call.
