A telecommunications company recently compromised 1.6 million records due to a phone call.
Have I Been Pwned has recorded the leaked data, and The Register reported the breach on August 14. Its cybersecurity editor, Jessica Lyons, wrote the article. A spokesperson for ShinyHunters informed her that the group gained access by voice-phishing an employee. There was no technical exploit or unaddressed vulnerability; it simply required a phone call.
The significant aspect to note is what RingCentral offers. As a cloud communications provider, its primary product is business phone services.
What the company stated
RingCentral announced the breach on July 28 through a general advisory on its trust center. They described the incident as “a sophisticated social engineering campaign” and indicated they acted to halt the unauthorized activities as soon as they were detected. They also enlisted a prominent third-party forensic firm, adding that they have not observed any new unauthorized activities since then.
The timing is notable. ShinyHunters posted its listing on July 27, and the advisory was dated the following day. The company has not publicly identified its attacker.
The notice outlines the scope carefully. The incident impacted data for “a limited portion” of customers, and the company is directly contacting those affected. If RingCentral has not reached out to you, this means you are likely not impacted.
It also defined the parameters regarding the product itself. The core platform was not affected by the incident, and services continued without disruption. RingCentral did not promptly respond to The Register's request for comments regarding the data dump.
The countdown that expired
ShinyHunters listed RingCentral on its leak site on July 27. This post claimed to contain over 623GB of data and set a deadline of July 30, under a banner reading “final warning pay or leak.” The last line advised: make the right decision, don’t be the next headline.
No one paid. On August 3, the group posted again, expressing frustration that the company did not reach an agreement despite their significant patience and multiple offers. They then proceeded to release the data.
Another major firm on the same list
RingCentral was not the only company targeted that week. Ernst & Young appeared alongside it on July 27, with its own deadline of July 31 and a more direct message: “Yes it was us,” before promising to release all data and documents.
Security researcher Dominic Alvieri flagged both listings on the same day. Dark Web Intelligence identified seven additional names, including Abbott’s Exact Sciences, Brinks Home, Ingram Content Group, Fluke, and Glendale Community College.
Ten days earlier, EY had already disclosed its own breach involving a third-party support ticket system, which occurred from late March to April, and included client tax information. It remains unclear whether ShinyHunters is linking that incident to its current claims or if it refers to a different breach, as the wording of its post could suggest either interpretation.
A persistent tactic
This has become a pattern rather than an isolated event. ShinyHunters has targeted hundreds of organizations since January, with Alvieri identifying it as his top threat group, likely echoing the views of many analysts.
Last week, the group leaked 10.9 million email addresses from Abbott's cancer diagnostics division, along with personal and health information, using the same method—by calling staff and convincing them to grant access. Previous victims include the Moody Bible Institute, where 2.3 million accounts were exposed, and Medtronic, the pacemaker manufacturer.
The same approach was seen with Levi Strauss this month, where attackers used social engineering to gain access to three computers, without exploiting any software vulnerability. Just three machines were sufficient for their objectives.
When they do exploit software, it can be even more damaging
The group is not confined to phone tactics. In June, it exploited more than 100 organizations through an unpatched Oracle PeopleSoft zero-day, rated 9.8 and exploitable over the internet without authentication.
Approximately two-thirds of the affected entities were universities and colleges, spanning about 300 servers. The breach resulted in hundreds of thousands of student records being compromised, including birthdates, enrollment statuses, and GPAs.
When comparing the two campaigns, the economics are evident. A zero-day vulnerability requires extensive research and is quickly neutralized once patched, while a phone call incurs no cost and remains effective indefinitely. Only one of these tactics necessitates any technical knowledge from the attacker.
This trend is becoming widespread
Voice phishing has become a common technique against large corporations. A recent campaign targeted some of the most prominent names in finance, including Blackstone, KKR, and CME, using nothing more sophisticated than a phone call.
Mass extortion efforts are also crowded. The Russia-linked group Cl0p announced a fresh wave of attacks this week, naming Shell and Philips among their victims.
What connects these groups is the target rather than the methods. All of them focus on individuals who can be persuaded, a category that no patch cycle can safeguard against.
Other articles
A telecommunications company recently compromised 1.6 million records due to a phone call.
ShinyHunters exposed 1.6 million records of RingCentral customers, claiming they gained access by using voice phishing to obtain a password from an employee.
