1.6M RingCentral accounts' data dumped after ShinyHunters extortion attack
Another one bites the dust
Some 1.6 million RingCentral user email addresses were leaked online in an attack that the collaboration software company alleged was the result of a social engineering campaign. RingCentral confirmed the breach on July 28 and said the attack had impacted a "limited portion of RingCentral customers." The company swiftly responded to the intrusion, halted unauthorized activity, and initiated a forensic investigation.
RingCentral has not disclosed who the perpetrator is, but the data leak site linked to the breach has previously been used by ShinyHunters, a notorious cybercriminal group. ShinyHunters claimed they stole over 623 GB of data and provided a deadline for the company to pay a ransom or face the release of the stolen information online. RingCentral did not comply with the extortion demand, and ShinyHunters followed through on their threat, posting the customers' details on the internet on August 3.
According to a ShinyHunters spokesperson, they gained access to RingCentral by voice-phishing an employee, who unknowingly provided the group with their password. This same group has targeted numerous organizations since the beginning of the year, including educational technology companies for schools and healthcare organizations.
Recently, ShinyHunters leaked data from Abbott's cancer diagnostics business, which contained 10.9 million unique email addresses, personal information, health details, and medical records, including doctor-patient conversations, prescription information, and refill details.
The cybercriminal group has not commented on the specifics of this latest breach. RingCentral declined to comment further on this story, but a spokesperson will provide additional information if requested.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.