1.6m customer records exposed in RingCentral data leak
ShinyHunters breached the phone company by voice-phishing a single staff member
RingCentral, a company that sells business phone systems, was breached by a phone call. The extortion group ShinyHunters says it got in by voice phishing a single staff member; no exploit and no unpatched flaw were required.
Have I Been Pwned has now logged 1.6 million leaked records tied to the incident, first reported by The Register's Jessica Lyons on 14 August.
A phone call was all it took
The incident was made known by RingCentral on 28 July through an advisory posted on its trust centre, noting the security threat to be "a sophisticated social engineering campaign".
According to RingCentral, it was able to stop the activity on detection and engaged forensics specialists from external sources, after which it has been observing no more unauthorised activities.
It has been stated that the breach has only affected "a limited portion" of its customers, whom it is contacting, and that the main platform has not been affected at all.
ShinyHunters listed RingCentral on its leak site on 27 July, claiming more than 623 GB of stolen data and setting a 30 July deadline under the banner "final warning: pay or leak".
When RingCentral didn't pay, the group returned on 3 August, accusing the company of failing to reach an agreement "despite our incredible patience", before publishing the data.
Ernst & Young appeared on the same leak site that week with a blunter message: "Yes, it was us."
EY had separately disclosed its own breach ten days earlier, involving a third-party support ticket system and client tax documents, though it remains unclear whether the two incidents are connected.
Security researcher Dominic Alvieri calls ShinyHunters his top threat group, and the RingCentral breach fits a pattern the group has repeated all year.
It used the same phone-based technique last week against Abbott's cancer diagnostics business, exposing 10.9 million email addresses along with health information, and earlier against the Moody Bible Institute and pacemaker maker Medtronic.
The harm is different when the group decides to use software, since in June it launched an unauthenticated zero-day exploit against Oracle PeopleSoft, which affected over 100 organisations, largely universities, leaving hundreds of thousands of students data exposed.
Voice phishing is now moving on to Blackstone, KKR and CME, none of which had to be breached through any technical exploits at all.
Contact details obtained during such breaches as that of RingCentral directly feed into subsequent phone calls.
-
Excel's new copilot feature turns data into live dashboard
-
OpenAI, Microsoft sued by US newspapers over AI training
-
Musk's xAI loses court bid to block Minnesota’s strict Deepfake pornography ban
-
Google launches Lyria 3.5: Everything you need to know about its AI music model
-
Altman says curing cancer isn't ambitious enough for AI
-
US turns to AI productivity as worker income share hits record low
-
Apple’s iPhone Ultra reportedly won’t include black option
-
DeepSeek plans massive Huawei chip order for Mongolia data center