News

RingCentral breach: 1.6 million contact records leaked, and why that matters for your phone system

RingCentral, one of the larger hosted phone and messaging platforms, disclosed in late July that it had been compromised through what it called a sophisticated social engineering campaign. It hasn't said exactly how the attackers got in.

In August, Have I Been Pwned analysed the leaked files and found records for around 1.6 million accounts: names, email addresses, phone numbers and postal addresses.

Why this is more than a privacy story

None of that data is a password. But it's precisely what a scammer needs to ring your office, say they're from RingCentral support, and already know your name, number and address. That call sounds legitimate, and it's the opening move for getting a password reset, an MFA change or remote access approved.

What to do

  • Never approve a password reset, a change to multi-factor authentication, or a remote access request on the back of an unexpected call. End the call and ring the provider back on the number from its own website.
  • If you use RingCentral, or any hosted phone system, check whether your addresses appear on Have I Been Pwned. Being listed doesn't mean your account is compromised; it means expect targeted calls.
  • Brief reception and anyone who answers the main line. They're the ones who will take the call.

Unsure whether a support call or email is real? Forward the details to us before you respond and we'll verify it.

Want a hand with this? Talk to us.

Source: BleepingComputer: RingCentral data breach exposed info of 1.6 million accounts

← All insights