Enormous RingCentral Data Breach: A Geordie’s Perspective
Approximately 1.6 million distinct email addresses linked to RingCentral have been exposed online, along with names, physical addresses, and phone numbers, as reported by Have I Been Pwned. RingCentral acknowledged the breach on July 28, stating that “it was subjected to a complex social engineering scheme” impacting a “limited segment of RingCentral users.” The communications platform mentioned that it acted swiftly against the breach upon discovery, “implemented measures to cease the unauthorized actions,” and immediately initiated an inquiry into the security breach with assistance from a “prominent third-party forensic agency.” “We have not observed any new unauthorized actions since initiating these corrective steps,” the company stated.
The Quiet Response
RingCentral did not promptly reply to GadgetLad’s inquiry regarding this information. We will revise it as necessary. Although the company has not disclosed the identity of its assailant, the infamous data theft and extortion group ShinyHunters had previously asserted it breached the collaboration platform, according to a notice on its data leak website, which GadgetLad reviewed. Images of the notice also spread on social media.
ShinyHunters: The Offenders
The perpetrators claimed to have taken over 623 GB of information and established a July 30 deadline for RingCentral to comply with their demands – or else the gang would release the stolen data online. Evidently, RingCentral did not satisfy the extortion request, and ShinyHunters carried out its threat, disseminating customer information on the web. “The company failed to negotiate with us despite our remarkable patience, all the opportunities and proposals we presented. They don’t care,” the criminals posted on August 3.
How Did They Achieve It?
A spokesperson for ShinyHunters informed us that the group infiltrated RingCentral by voice-phishing an employee and deceiving them into providing their password. This same group, which security analyst Dominic Alvieri identifies as his “primary threat group and likely is for numerous analysts,” has breached hundreds of organizations since the beginning of the year, targeting educational technology firms serving schools and universities as well as healthcare entities.
ShinyHunters’ Notable Incidents
Recently, ShinyHunters released data acquired from Abbott’s cancer diagnostics division, with the leak encompassing 10.9 million unique email addresses along with personal and health details. The offenders assert they absconded with over 30 million rows of client information, including more than one million Social Security numbers and 7.5 million birth dates. More alarmingly, they indicated that the collection includes over 22 million rows of client notes containing private doctor-patient dialogues and health information, alongside more than 20 million medical order records with patient IDs, prescription types, order dates, and refill data.
Overview: When Your Information Becomes More Notable Than You
If you have your life’s details stored on RingCentral, then ShinyHunters has just bestowed upon you an unwelcome dose of notoriety. It makes you wish your data was as unpopular as a workout after a night out on the town! Stay cautious out there, everyone, and perhaps consider updating that password, eh?