ShinyHunters breached the phone company by voice-phishing a single staff member
RingCentral, a company that sells business phone systems, was breached by a phone call. The extortion group ShinyHunters says it got in by voice phishing a single staff member; no exploit and no unpatched flaw were required.
Have I Been Pwned has now logged 1.6 million leaked records tied to the incident, first reported by The Register's Jessica Lyons on 14 August.
The incident was made known by RingCentral on 28 July through an advisory posted on its trust centre, noting the security threat to be "a sophisticated social engineering campaign".
According to RingCentral, it was able to stop the activity on detection and engaged forensics specialists from external sources, after which it has been observing no more unauthorised activities.
It has been stated that the breach has only affected "a limited portion" of its customers, whom it is contacting, and that the main platform has not been affected at all.
ShinyHunters listed RingCentral on its leak site on 27 July, claiming more than 623 GB of stolen data and setting a 30 July deadline under the banner "final warning: pay or leak".
When RingCentral didn't pay, the group returned on 3 August, accusing the company of failing to reach an agreement "despite our incredible patience", before publishing the data.
Ernst & Young appeared on the same leak site that week with a blunter message: "Yes, it was us."
EY had separately disclosed its own breach ten days earlier, involving a third-party support ticket system and client tax documents, though it remains unclear whether the two incidents are connected.
Security researcher Dominic Alvieri calls ShinyHunters his top threat group, and the RingCentral breach fits a pattern the group has repeated all year.
It used the same phone-based technique last week against Abbott's cancer diagnostics business, exposing 10.9 million email addresses along with health information, and earlier against the Moody Bible Institute and pacemaker maker Medtronic.
The harm is different when the group decides to use software, since in June it launched an unauthenticated zero-day exploit against Oracle PeopleSoft, which affected over 100 organisations, largely universities, leaving hundreds of thousands of students data exposed.
Voice phishing is now moving on to Blackstone, KKR and CME, none of which had to be breached through any technical exploits at all.
Contact details obtained during such breaches as that of RingCentral directly feed into subsequent phone calls.