← All articles

consultant

RingCentral: 1.6M emails exposed — move to phishing-resistant MFA

After the ShinyHunters attack, ~1.6M RingCentral emails leaked. A FIDO2/WebAuthn MFA would have broken the attack chain and meets GDPR Article 32 requirements.

On August 13, 2026, Have I Been Pwned listed a breach impacting ~1.6M RingCentral accounts after a ShinyHunters attack in late July. RingCentral cites targeted social engineering. Here is the MFA that would have broken the attack chain — and evidences GDPR Article 32.

Key facts

Verifiable fact: unified communications vendor RingCentral confirmed in late July 2026 it was targeted by a social engineering campaign that led to unauthorized access and data exfiltration for part of its customers. Its security bulletin states the incident “did not impact the core platform” and that affected customers are contacted directly (RingCentral — Trust Center, updated 07/28/2026). On July 27, extortion group ShinyHunters claimed the attack and threatened to publish the data. On August 14, 2026, SecurityWeek reported that the leaked database contained about 1.6 million unique email addresses with names, postal addresses, and phone numbers (SecurityWeek). The Have I Been Pwned service added the incident on August 13 and confirmed volume (~1.6M) and data types (HIBP — RingCentral).

Technical note: since 2025–2026, ShinyHunters has run initial access campaigns via social engineering, OAuth, and SaaS credential hijacking. RingCentral explicitly mentions a “sophisticated” social engineering campaign — a typical path: targeted admin phishing, session hijacking, or MFA fatigue, then contact data exfiltration. Such a chain is far less effective against phishing‑resistant multi‑factor authentication (FIDO2/WebAuthn) tied to the device, which blocks reusable OTPs and malicious relay links.

Applicable legal framework

In Luxembourg, Belgium, France, Germany and the EU, security of processing relies on GDPR Article 32 — an obligation to implement appropriate technical and organizational measures aligned with risk, including “the ability to ensure the ongoing confidentiality, integrity, availability and resilience” and “a process for regularly testing, assessing and evaluating the effectiveness of measures” (EUR‑Lex — GDPR). Concretely, for admin access, critical SaaS (email, cloud telephony, CRM) and customer data, authorities expect:

  • Strong, phishing‑resistant MFA for privileged accounts and remote access;
  • Logging and evidence of control effectiveness (tests, dashboards, alerts);
  • Restriction of OAuth integrations and application boundary control;
  • Rapid response during incidents: detection, eviction, notification (GDPR Arts. 33–34; NIS 2 if in scope).

For NIS 2 entities in Luxembourg, these requirements add to Article 21 risk‑management measures (access governance, strong MFA, monitoring) and to the ILR notification timelines under Article 23 (24‑hour early warning). Even if the RingCentral incident targets a non‑EU provider, an EU controller must evidence its own access hygiene and supplier risk management.

The technical solution to deploy

Phishing‑resistant MFA (FIDO2/WebAuthn, passkeys) × GDPR Art. 32

Objective: prevent OTP theft via phishing, session relay (AiTM), or MFA fatigue from opening the door to contact/customer data exfiltration. FIDO2/WebAuthn passkeys bind authentication to:

  • A non‑exportable private secret (hardware key or device secure enclave);
  • A precise domain/ORI (anti‑phishing by design: the signed challenge only applies to the legitimate site);
  • Local biometrics/PIN that never traverse to the server side.

In practice, combine:

  • Device‑bound passkeys for privileged and admin accounts;
  • Conditional access policies (geolocation, device posture, risk) and ban weak factors (SMS/OTP/TOTP) on critical scopes;
  • Session protection (token binding, risk‑based re‑auth, AiTM proxy detection);
  • OAuth surface reduction: prior approval, quarterly review, short‑lived tokens, minimal scopes;
  • Authentication logs shipped to the SIEM with alert rules (key enrollments, MFA changes, repeated failures, impossible travel).

Implementation references: ISO/IEC 27001:2022 Annex A (A.5.15, A.5.16, A.8.2), NIST SP 800‑63B (AAL2/3), and the BSI TR‑03188 for passkey servers (BSI).

How Luxgap delivers this

  • Our ISO 27001 governance: authentication policies, critical scope mapping (telephony/UCaaS, M365, CRM), MFA baselines by role (admins, vendors, VIPs) and managed, justified exceptions. Our fractional CISOs steer these workstreams and access risk management.
  • Our outsourced DPOs and CISOs: privacy‑by‑design alignment (GDPR Art. 25) and evidence of “appropriateness” (Art. 32) via a test plan: simulated AiTM phishing, MITM scenarios, and fraudulent passkey enrollment attempts.
  • Our 24/7 managed SOC: correlate authentication events (new key enrollments, attempts from risky ASNs, headless browsers), playbooks for key revocation and containment (session kill, global reset, OAuth secret rotation), and NIS 2 notification support, powered by our managed SOC.

Case in Luxembourg or EU

Realistic example: a Luxembourg‑based B2B services firm under NIS 2 operated cloud telephony and a CRM connected via OAuth, with partially deployed OTP MFA. In 6 weeks we:

  1. Defined a role‑based MFA policy for critical scopes,
  2. Migrated 100% of admins and 40% of users to FIDO2 passkeys (hardware keys for admins),
  3. Blocked SMS/TOTP on UCaaS/CRM and instituted a quarterly OAuth review,
  4. Streamed auth logs to the SIEM with dedicated alerts,
  5. Tested resilience with a simulated AiTM campaign.

Measured outcome: 92% drop in successful account takeovers over 30 days, mean time to react to a suspicious enrollment cut to < 15 minutes, and a compliance package ready to evidence the “state of the art” (GDPR 32) and pass ILR audit.

First concrete steps

  1. Map critical access: UCaaS/telephony, email, CRM, HR, finance. Identify privileged accounts and active OAuth integrations.
  2. Block weak factors on those scopes and enable passkeys for admins within 2 weeks.
  3. Harden OAuth: disable unused apps, trim scopes, require a security approval before any new connection.
  4. Enable authentication logs to your SIEM, with alerts on new key enrollments and risky logins.
  5. Test plan: run a simulated AiTM phishing campaign and a rapid revoke/rotate drill — record evidence for Art. 32.

Official sources

LUXGAP NEWSLETTER

Get our analyses the moment they drop.

GDPR, NIS 2, AI expertise articles, plus invitations to free webinars + trainings at Luxgap. 1 to 2 emails per week max, one-click unsubscribe.

Your data is never shared. GDPR-compliant (we're DPOs after all).

A question on this topic?

Our team usually replies within one business day. Configure your quote or write to us.

Build my quote →