Have I Been Pwned logged the leaked records, and The Register reported the dump on 14 August. Jessica Lyons, its cybersecurity editor, wrote it. A ShinyHunters spokesperson told her the group broke in by voice-phishing a member of staff.

There was no exploit and no unpatched flaw. Someone picked up the phone.

The detail that makes this land is what RingCentral sells. It is a cloud communications company, and its product is the business telephone.

What the company has said

RingCentral disclosed the intrusion on 28 July, in a general advisory notice on its own trust centre. It called the attack “a sophisticated social engineering campaign” and said it moved to stop the unauthorised activity on detecting it. It also brought in a leading third-party forensic firm, and says it has seen no new unauthorised activity since.

The timing is worth a moment. ShinyHunters posted its listing on 27 July, and the advisory carries the following day’s date. The company has never named its attacker.

The notice is careful about scope. The incident touched data for “a limited portion” of customers, the company said, and it is contacting those customers directly. If RingCentral has not been in touch, you are not affected.

It also drew a line around the product itself. The incident did not touch the core platform, and services carried on without disruption. RingCentral did not immediately respond to The Register’s request for comment on the dump.

The countdown that ran out

ShinyHunters listed RingCentral on its leak site on 27 July. The post claimed more than 623GB of data and set a deadline of 30 July, under a banner reading “final warning pay or leak”. Its closing line was a piece of advice: make the right decision, don’t be the next headline.

Nobody paid. On 3 August the group posted again, complaining that the company had failed to reach an agreement “despite our incredible patience, all the chances and offers we made”. Then it published the data.

A Big Four firm on the same list

RingCentral was not alone on the board that week. Ernst & Young appeared beside it on 27 July, with its own deadline of 31 July and a blunter message. “Yes it was us,” the listing began, before promising to release all the data and files.

The security researcher Dominic Alvieri flagged both listings the same day. Dark Web Intelligence counted seven new names, including Abbott-owned Exact Sciences, Brinks Home, Ingram Content Group, Fluke and Glendale Community College.

EY had already disclosed a breach of its own ten days earlier, involving a third-party support ticket system. That intrusion ran from late March into April, and the documents involved contained client tax information. Nobody has yet established whether ShinyHunters is claiming that incident or a separate one, and the phrasing of its post cuts both ways.

The same crew, the same phone call

This is now a pattern rather than an incident. ShinyHunters has hit hundreds of organisations since January, and Alvieri calls it his top threat group, adding that it probably is for most analysts.

Last week it dumped 10.9 million email addresses taken from Abbott’s cancer diagnostics business, alongside personal and health information. It reached that company the same way, by calling staff and talking them into granting access. Earlier victims include the Moody Bible Institute, where 2.3 million accounts spilled, and the pacemaker maker Medtronic.

The desk saw the identical method at Levi Strauss this month. Attackers used social engineering to reach three computers, with no software vulnerability involved at any point. Three machines were enough.

When it does use software, it is worse

The group is not limited to the telephone. In June it breached more than 100 organisations through an unpatched Oracle PeopleSoft zero-day, rated 9.8 and exploitable over the internet without authentication.

Roughly two-thirds of those victims were universities and colleges, across some 300 servers. The haul ran to hundreds of thousands of student records, including birthdates, enrolment status and grade point averages.

Put the two campaigns side by side and the economics are obvious. A zero-day takes research and burns out the moment a patch lands, while a phone call costs nothing and never stops working. Only one of those two requires the attacker to know anything technical at all.

Everyone is doing this now

Voice phishing has become a mainstream technique against large firms. A campaign this month went after some of the most sophisticated names in finance, with Blackstone, KKR and CME among the targets, using nothing more advanced than a telephone.

Mass extortion is crowded too. The Russia-linked group Cl0p claimed a fresh wave of attacks this week, naming Shell and Philips among its victims.

What links these groups is the target rather than the tooling. All of them go after the person who can be persuaded, which is a category no patch cycle addresses.

What 1.6 million people should expect next

The data now circulating is not passwords. It is names, email addresses, physical addresses and phone numbers, which is the raw material for the next round of convincing calls and emails.

Valve went through this in the same week and told its customers exactly that. A breach at its logistics provider left buyers exposed, and the company warned them directly that scammers have their address.

The uncomfortable part is the loop. Stolen contact details make the next voice-phishing call more credible, and the next call produces the next set of stolen contact details.

What would settle it

Three things, and the first is the number. RingCentral says a limited portion of customers was affected, Have I Been Pwned has logged 1.6 million addresses, and those two statements need reconciling.

The second is EY. The firm has not publicly linked the ShinyHunters listing to the breach it disclosed in July, and it is the only party that can settle the question.

The third is whether anything changes on the phones. Every organisation on that leak site had a security programme, and a caller got through anyway.

Get the TNW newsletter

Get the most important tech news in your inbox each week.