PrivacySignal
Breach

RingCentral data breach exposed info of 1.6 million accounts

BleepingComputer · · International · Data Breaches

The ShinyHunters extortion group breached RingCentral in July and stole personal information from 1.6 million accounts, according to data breach notification service Have I Been Pwned.

Why this matters: RingCentral is a business phone and messaging platform, which means the exposed accounts likely belong to employees and organizations, not just individual consumers. That changes the blast radius. Work accounts carry contact details, company affiliations, and communication metadata that can be used to target people professionally. ShinyHunters does not just steal data and disappear — extortion is the business model. If you or your company uses RingCentral, assume the affected data is already in circulation and act accordingly.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · Policy

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

The Attacker Did Not Need to Sleep

Spain received its first reported personal-data breach carried out by an AI agent. The techniques were familiar. The speed and autonomy were not.

· 4 min read Read →

Related stories

Breach
DataBreaches.net · · International

Hogan Lovells Cadwalader hacked by Silent Ransom Group; re-attacked after they wouldn’t pay

Numerous major law firms have fallen prey to the Silent Ransom Group this year. Now DataBreaches provides exclusive details on SRG’s recent attacks on Hogan Lovells Cadwalader. Yes, that’s “attacks,” plural. When New York City’s oldest law firm, Cadwalader, Wickersham & Taft, merged with Hogan Lovells in 2022, it combined two powerhouse firms. Yet despite... Source

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
BleepingComputer · · International

JadePuffer agentic AI attacks target Azure, destroy cloud resources

The JadePuffer ransomware operator is targeting Azure tenants with agent-driven attacks that conduct reconnaissance, steal credentials, and destroy core components. [...]

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#ai#security Read original →
Breach
DataBreaches.net · · International

Former U.S. Soldier Sentenced for Hacking and Extortion Scheme That Exposed Sensitive Data of U.S. Government Official

September 25 – U.S. Department of Justice: Cameron John Wagenius, 22, a former Army soldier who was most recently stationed in Texas, was sentenced today to 70 months in prison and ordered to pay $294,978 in restitution for conspiring to hack into telecommunications companies’ databases, access sensitive records, and extort the companies by threatening to... Source

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
Krebs on Security · · International

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation

Dutch police arrested a 23-year-old with a prior cybercrime conviction on suspicion of supporting ShinyHunters, a hacker group known for large-scale data theft and extortion. Shortly after the arrest, other ShinyHunters members reportedly escalated activity, including stealing data from the FBI and targeting ransomware group Cl0p.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#enforcement#security Read original →