RingCentral, one of the larger hosted phone and messaging platforms, disclosed in late July that it had been compromised through what it called a sophisticated social engineering campaign. It hasn't said exactly how the attackers got in.
In August, Have I Been Pwned analysed the leaked files and found records for around 1.6 million accounts: names, email addresses, phone numbers and postal addresses.
Why this is more than a privacy story
None of that data is a password. But it's precisely what a scammer needs to ring your office, say they're from RingCentral support, and already know your name, number and address. That call sounds legitimate, and it's the opening move for getting a password reset, an MFA change or remote access approved.
What to do
- Never approve a password reset, a change to multi-factor authentication, or a remote access request on the back of an unexpected call. End the call and ring the provider back on the number from its own website.
- If you use RingCentral, or any hosted phone system, check whether your addresses appear on Have I Been Pwned. Being listed doesn't mean your account is compromised; it means expect targeted calls.
- Brief reception and anyone who answers the main line. They're the ones who will take the call.
Unsure whether a support call or email is real? Forward the details to us before you respond and we'll verify it.
Want a hand with this? Talk to us.
Source: BleepingComputer: RingCentral data breach exposed info of 1.6 million accounts