September 8, 2026
By esentry Team

Right Inbox Breach Allegedly Exposes 121,000 User Profiles

Threat Overview

A threat actor has allegedly claimed responsibility for a breach of Right Inbox, a productivity platform that integrates with Gmail to provide email tracking, scheduling and automation features. The actor claims to have obtained information belonging to approximately 121,000 user profiles and has allegedly offered the data for sale on a cybercrime forum.

The reported exposure raises concerns because information associated with email productivity platforms can provide attackers with valuable data for phishing, account targeting and social engineering.

Key Points

  • Approximately 121,000 Right Inbox user profiles are allegedly exposed.
  • The breach claim has reportedly been posted by a threat actor on a cybercrime forum.
  • The exposed information is alleged to contain user-profile data associated with Right Inbox accounts.
  • The breach remains an allegation and should not be treated as independently confirmed without verification from Right Inbox.
  • If authentic, exposed user information could support targeted phishing and impersonation campaigns.

Potential Impact

The primary concern is not simply the number of profiles allegedly exposed, but how the information could be used.

Threat actors could use legitimate-looking user information to create more convincing phishing messages, identify potential targets and conduct account-focused social engineering.

For organizations using Right Inbox, compromised user information could also increase the risk of business email compromise (BEC) attempts, particularly where exposed information can be combined with data from other breaches.

Recommendations

Organizations and users should:

  • Monitor Right Inbox-related accounts for suspicious login or account activity.
  • Be cautious of unexpected emails referencing Right Inbox, account changes or password resets.
  • Avoid reusing passwords across Right Inbox and other services.
  • Enable MFA where available.
  • Review email forwarding rules and other account settings for unauthorized changes.
  • Monitor for further publication or sale of the alleged dataset.
  • Treat the breach as unconfirmed until independently validated by Right Inbox or another reliable source.

Intelligence Takeaway

The alleged Right Inbox exposure demonstrates how seemingly routine productivity platforms can become valuable sources of information for threat actors.

If the dataset is authentic, the combination of 121,000 user profiles and email-related context could provide attackers with a useful foundation for targeted phishing and social-engineering activity.

At this stage, however, the claim remains unverified and should be monitored for further evidence or an official disclosure.