RingCentral data breach exposed info of 1.6 million accounts
RingCentral, a cloud-based collaboration and communication platform, has suffered a data breach exposing information of 1.6 million accounts. The breach was carried out by the ShinyHunters extortion group, who stole personal information, including names, email addresses, …
Intelligence analysis by Llama

RingCentral has been the target of a sophisticated social engineering campaign, resulting in a data breach that has exposed information of 1.6 million accounts. The company has not attributed the breach to a specific threat actor or hacking group, but the ShinyHunters extortion gang has claimed responsibility.
Imagine you have a big box of files with important information about you, like your name, email, and phone number. Someone breaks into the box and takes all the files, including the information about you. That's what happened to RingCentral, a company that helps other businesses communicate. The bad guys, called ShinyHunters, took information about 1.6 million people's accounts and put it online for anyone to see.
Analysis
Background
The ShinyHunters extortion group has been linked to several high-profile data breaches in recent months, including breaches at hundreds of Salesforce customers and over a dozen Snowflake customers. The group has claimed responsibility for stealing over 1.5 billion records in Salesloft Drift and Salesforce Aura campaigns.
What Changed
RingCentral, a cloud-based collaboration and communication platform used by over 600,000 businesses, has suffered a data breach exposing information of 1.6 million accounts. The breach was carried out by the ShinyHunters extortion group, who stole personal information, including names, email addresses, phone numbers, and physical addresses. The company has not attributed the breach to a specific threat actor or hacking group, but the ShinyHunters extortion gang has claimed responsibility.
What's Next
RingCentral has taken remediation efforts to prevent further unauthorized activity, but the company has yet to share further details on the incident. The ShinyHunters extortion group has leaked a compressed archive containing 280GB worth of files on their dark web leak site, which has been confirmed by Have I Been Pwned to contain records for 1.6 million accounts.
Key points
- RingCentral has suffered a data breach exposing information of 1.6 million accounts.
- The breach was carried out by the ShinyHunters extortion group, who stole personal information, including names, email addresses, phone numbers, and physical addresses.
- RingCentral has not attributed the breach to a specific threat actor or hacking group, but the ShinyHunters extortion gang has claimed responsibility.
- The company has taken remediation efforts to prevent further unauthorized activity, but has yet to share further details on the incident.
RingCentral has taken steps to prevent further unauthorized activity, and the company's services continue to operate without disruption. The ShinyHunters extortion group's actions may be seen as a warning to other companies to improve their security measures and prevent similar breaches.
The data breach has exposed sensitive information about 1.6 million people, which could lead to identity theft, phishing, and other malicious activities. The ShinyHunters extortion group's actions may be seen as a sign of a larger problem with cloud-based platforms and their vulnerability to data breaches.


