A threat actor claims to have breached Right Inbox, a Gmail productivity platform, and released data allegedly containing 121,616 unique user profiles alongside approximately 39.47 million activity records.
The actor claims the breach occurred on Aug. 29 and has made the dataset available for download. According to the post, the leaked information includes email addresses, user identifiers, IP addresses, approximate location information, subscription details, device information and application activity.
The claim is particularly notable because the same threat actor says they were responsible for previously reported breaches involving Mailshake and ZoomShift. BreachNews covered both incidents before the actor began using their current alias.
39 million activity records allegedly exposed
The actor claims the Right Inbox dataset is divided into 2 primary exports. One allegedly contains 121,616 deduplicated user profiles, while the second contains approximately 39,471,186 activity records associated with those users.
According to the fields disclosed by the actor, the profile and activity information may include:
- Email addresses and internal user identifiers
- IP addresses
- Cities, regions and countries
- Approximate geographic coordinates
- Subscription plans and payment status information
- Subscription dates
- Device brands, models and types
- Operating system names and versions
- Application versions and language settings
- Other user and application properties
The actor claims the unique profile dataset contains 121,616 email addresses and user identifiers associated with 84,836 unique IP addresses across 219 countries.
The approximately 39.47 million figure refers to activity records rather than unique people. Based on the actor’s description, the alleged breach therefore appears to involve approximately 121,616 unique profiles with multiple events associated with individual accounts.
BreachNews is not linking to or distributing the leaked database.
Actor links claim to Mailshake and ZoomShift breaches
The threat actor explicitly connected the Right Inbox leak to 2 previous incidents involving companies associated with the same business network.
In July, BreachNews reported that Mailshake was allegedly breached, with the actor claiming to have obtained data associated with 49,178 users along with internal administrative information.
BreachNews also covered the actor’s ZoomShift breach claim, which allegedly exposed information associated with 10,507 users as well as employee and GPS clock-in data.
In the new Right Inbox post, the actor claims responsibility for both previous incidents and says they are now operating under a different alias after losing access to accounts associated with their former identity.
BreachNews is not publishing either of the actor’s individual aliases. The connection between the incidents is based on the actor’s own attribution and has not been independently confirmed.
Right Inbox integrates directly with Gmail
Right Inbox provides a browser extension that integrates with Gmail and adds features including email scheduling, tracking, reminders, recurring messages, templates, follow-up sequences and CRM synchronization.
The company says more than 250,000 professionals have added Right Inbox to Gmail.
Right Inbox also has an existing integration with Mailshake that allows users to manage Mailshake campaigns from within Gmail. The companies have publicly described Right Inbox and Mailshake as sister companies.
The available breach claim does not establish that Gmail credentials, Google account passwords or the contents of users’ emails were compromised. The fields published by the actor instead appear primarily related to Right Inbox account profiles, subscriptions, devices, locations and application activity.
Location and activity data increase privacy concerns
The alleged exposure of IP addresses and geographic information adds a privacy dimension beyond the disclosure of email addresses alone.
If authentic, the combination of account identifiers, subscription information, IP addresses, approximate locations, device characteristics and application activity could help attackers construct more convincing phishing or social engineering campaigns targeting Right Inbox users.
The actor’s claim of approximately 39.47 million activity records could also provide considerably more behavioral information than the 121,616-profile count suggests, although BreachNews has not independently verified the completeness or authenticity of the released dataset.
Right Inbox had not issued any public statement addressing the alleged breach at time of publication.












