Urgent.News

600+ sources. One page. See who else covered it.

Editions

Tech

1.6M RingCentral accounts' data dumped after ShinyHunters extortion attack

Another one bites the dust

1.6M RingCentral accounts' data dumped after ShinyHunters extortion attack

The communication platform RingCentral suffered a data breach that exposed the personal information of over 1.6 million users, including email addresses, physical addresses, and phone numbers, according to the leak detection service Have I Been Pwned. The company announced the attack on July 28, attributing it to a "sophisticated social engineering campaign" targeting a "limited portion of RingCentral customers."

Upon discovering the intrusion, RingCentral immediately took action to halt unauthorized access and initiated an investigation with the aid of a leading third-party forensic firm. The company claimed that no new unauthorized access had occurred since implementing these measures. However, the source did not provide comment on the breach.

Security experts believe that the data theft and extortion group ShinyHunters is responsible for the leak. ShinyHunters had previously alleged that they had compromised RingCentral, posting screenshots on their data leak site and social media. The group claimed to have stolen over 623 gigabytes of data and threatened to release it unless RingCentral paid an extortion demand by July 30.

RingCentral reportedly refused to pay the ransom, and ShinyHunters followed through on their threat on August 3, sharing the stolen customer details online. The group stated that RingCentral failed to reach an agreement with them despite their "incredible patience, all the chances and offers we made. They don't care."

A representative from ShinyHunters explained that they infiltrated RingCentral by voice-phishing an employee, who inadvertently provided the crooks with their password. ShinyHunters has targeted numerous organizations across various sectors since the beginning of the year, including education technology firms for schools and universities, healthcare organizations, and Abbott's cancer diagnostics business.

In a recent leak, the group released data containing 10.9 million unique email addresses, personal information, health details, and sensitive medical records, including 22 million physician-patient conversations and prescription information.

Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 1 other outlet

Read the original at theregister.com →

More in Tech

More from Friday 14 August →