
According to the data breach notification service Have I Been Pwned, the ShinyHunters extortion group reportedly stole personal information from 1.6 million RingCentral accounts after hacking the company in July. For context, RingCentral provides cloud-based communication services to over 600,000 businesses for calling, messaging, and voicemail. RingCentral confirmed the data breach in its security bulletin on July 28th.
RingCentral says the data breach affected only a limited number of customers
The company claims attackers compromised its systems in a “sophisticated social engineering campaign.” RingCentral clarifies that it has not detected any unauthorized activity since taking remediation efforts. But then it says the incident affected data belonging to only a limited number of customers and that it is contacting those customers directly.
If RingCentral hasn’t contacted you, it simply means that the data breach didn’t affect you. The incident apparently did not impact the core RingCentral platform, and its services continue to operate without disruption. RingCentral, in its security bulletin, did not name/attribute the breach to a specific threat actor or hacking group. It has yet to share more details on the incident.
But the ShinyHunters extortion gang claimed responsibility on July 27th. They claimed to have stolen 623GB of data. After RingCentral reportedly refused to pay a ransom, the group leaked a compressed 280GB archive of stolen files on its dark web leak site.

It’s not clear how attackers gained access
The company didn’t share a comment on ShinyHunters’ claims. However, Have I Been Pwned confirmed the data leak after analyzing it. The service said it contains records from 1.6 million accounts. This includes names, email addresses, phone numbers, and physical addresses.
RingCentral didn’t clearly reveal how the attackers gained access to its systems. ShinyHunters have carried out several major data breaches, including attacks on hundreds of Salesforce customers, more than a dozen Snowflake customers, and other third-party service providers. The group claims to have stolen over 1.5 billion records in Salesloft Drift and Salesforce Aura campaigns.
More recently, ShinyHunters claimed responsibility for data breaches at more than 100 organizations following data-theft attacks that exploited an Oracle PeopleSoft zero-day flaw.
The post RingCentral Confirms Data Leak Hitting 1.6 Million Accounts appeared first on Android Headlines.