ShinyHunters leaks 1.6M RingCentral accounts after extortion failure
TL;DR. ShinyHunters dumped data from 1.6 million RingCentral accounts online after the company refused to pay an extortion demand. - The data includes unique email addresses, names, physical addresses, and phone numbers. - RingCentral disclosed a 'sophisticated social engineering campaign' in late July. - ShinyHunters reportedly accessed RingCentral by voice-phishing an employee's password.
- ShinyHunters, a known cybercrime group, published data from 1.6 million RingCentral accounts.
- The leaked information includes email addresses, names, physical addresses, and phone numbers.
- The data dump occurred after RingCentral declined to pay an extortion demand from the attackers.
- RingCentral had previously reported a 'sophisticated social engineering campaign' affecting a 'limited portion of customers'.
- ShinyHunters claims to have gained access via voice-phishing an employee to obtain their password.
Sources
- 1.6M RingCentral accounts' data dumped after ShinyHunters extortion attack — theregister.com
- techcrunch.com — techcrunch.com