The Phone Call That Broke RingCentral

A significant data breach at RingCentral, a major cloud communications provider, has exposed the contact details of over 1.6 million customers. The stolen data, which includes names, email addresses, physical addresses, and phone numbers, was leaked by the notorious hacking group ShinyHunters after the company failed to meet an extortion deadline. The intrusion was not the result of a sophisticated software exploit or an unpatched flaw, but rather a simple yet highly effective social engineering attack, where the hackers successfully voice-phished a member of RingCentral’s staff over the telephone.

RingCentral, whose core product is the business telephone system, disclosed the intrusion on 28 July in a notice on its trust centre, describing it as a „sophisticated social engineering campaign.” The company stated it moved quickly to halt the unauthorized activity and engaged a leading third-party forensic firm, asserting that no new unauthorized activity has occurred since. The advisory was careful to scope the incident, saying it touched data for a „limited portion” of customers and that those affected are being contacted directly, while assuring that the core platform was not compromised and services continued without disruption. The company has not named the attacker, but the timing of ShinyHunters’ listing on 27 July, a day before the company’s advisory, suggests a direct link.

This attack is part of a broader, alarming pattern for ShinyHunters, which has targeted hundreds of organizations this year. The group, identified as a top threat by security analysts, has successfully used the same telephone-based social engineering tactic against other major entities, including Abbott’s cancer diagnostics business and Levi Strauss. The method is brutally effective and cheap, requiring no technical expertise when compared to developing or purchasing exploits like the Oracle PeopleSoft zero-day the group used in June to breach over 100 organizations, mostly universities. This shift highlights a disturbing trend where the human element, not technology, is the primary attack vector.

The leaked data from RingCentral, while not including passwords, is the raw material for future, more convincing phishing campaigns and scams. This creates a dangerous loop where stolen contact details make subsequent voice-phishing calls more credible, leading to more stolen data. As the fallout continues, three key questions remain: reconciling RingCentral’s „limited” scope with the 1.6 million addresses logged by Have I Been Pwned, clarifying whether the EY data dump is linked to its own disclosed breach, and ultimately, determining whether organizations will change their security cultures to defend against the persuasion tactics that are bypassing their technical safeguards.


Ez a cikk a Neural News AI (V1) verziójával készült.

Forrás: https://thenextweb.com/news/shinyhunters-ringcentral-leak-voice-phishing-ey.