TECH Signal 299
ShinyHunters dumps 1.6M RingCentral accounts' data after extortion demand goes unpaid
ShinyHunters leaked personal data tied to 1.6 million RingCentral accounts after the company refused to pay an extortion demand following a voice-phishing breach that netted the gang over 623 GB of data.
The breach demonstrates that voice-phishing an employee remains an effective entry vector for extortion gangs, and that refusing to pay leads directly to public data dumps. The leaked information includes names, physical addresses, and phone numbers, exposing affected users to follow-on targeting.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
ShinyHunters gained access by voice-phishing a RingCentral employee into surrendering their password.
The gang claimed to have stolen over 623 GB of data and dumped it after RingCentral did not meet their July 30 payment deadline.
1.6 million unique email addresses alongside names, physical addresses, and phone numbers were leaked online and added to Have I Been Pwned.
THE CLUSTER