Bottom line: A RingCentral data breach may have exposed 1.6 million users' sensitive information, raising significant concerns about the company's security posture.
What's happening: The hackers, claiming to be "Dark Crystal," published the allegedly stolen data on a public forum. The breach is believed to have occurred between June 2022 and July 2022. The attackers posted 1.4 million names, addresses, email addresses, and phone numbers, with no indication of passwords or financial data being compromised.
What to do: CISOs and security leaders should review RingCentral's security controls and incident response procedures to ensure the company is adequately addressing this breach and preventing similar incidents in the future. Additionally, they should consider implementing additional security measures, such as two-factor authentication, to protect their users' sensitive information.