RingCentral data breach hits 1.6 million users

Cloud communications provider RingCentral is investigating a July 2026 data breach after an extortion group published a trove of customer data linked to roughly 1.6 million accounts, including names, email addresses, phone numbers, and physical addresses.[1][3][10]

The incident stems from a “pay or leak” campaign attributed to the ShinyHunters cybercrime group, which listed RingCentral on its leak site in late July and threatened to release stolen files if a ransom demand was not met.[5][9][15] Subsequent reports from breach-tracking services and security outlets say the group ultimately dumped a large compressed archive of internal data on its leak site after RingCentral declined to pay.[3][10]

RingCentral publicly acknowledged a security incident on July 28, describing a compromise following what it called a sophisticated social engineering campaign against its systems.[3][6] The company has said that the breach affected data for a limited portion of its customers, that no new unauthorized activity has been observed since remediation steps were taken, and that the core RingCentral platform continues to operate without disruption.[2][3][6] Customers have been told they will be contacted directly if their data was involved and that those not notified are not considered affected.[2][3]

Independent breach monitors now estimate that the exposed dataset contains about 1.6 million unique email addresses tied to RingCentral accounts, accompanied by associated contact details.[1][7][8] One breach-aggregation site further lists Social Security numbers among the data types linked to the incident, though this specific claim has not been prominently echoed in other public reporting and may reflect only a subset of records.[11] Have I Been Pwned’s analysis indicates that roughly 44 percent of the email addresses in the dump were already present in its database from earlier breaches, underscoring how repeated compromises can amplify identity and fraud risks.[1][10]

While full technical details of the intrusion have not been disclosed, current reporting emphasizes social engineering rather than an exploit of a specific software vulnerability.[3][6] The campaign aligns with ShinyHunters’ broader playbook of data theft followed by extortion, in which attackers seek payment in exchange for withholding or deleting stolen information, then move to leak sites when targets refuse.[5][9][15] The publication of contact data at this scale significantly increases the likelihood of targeted phishing, business email compromise, and account takeover attempts against RingCentral customers and employees.[7][8]

Organizations that rely on RingCentral are being urged by breach trackers and industry observers to step up phishing awareness, enable multifactor authentication on all accessible accounts, and review email filtering and identity verification processes to catch suspicious login attempts and communications.[7][8][10] Affected individuals and companies should monitor for unusual activity tied to exposed email addresses and phone numbers, treat unsolicited messages referencing RingCentral as high-risk, and consider credential resets wherever the same passwords may have been reused across services.[1][10]

References

  1. RingCentral Data Breach
  2. RingCentral Security Bulletins
  3. RingCentral data breach exposed info of 1.6 million accounts
  4. RingCentral Listed by ShinyHunters
  5. Phishing service spoofs RingCentral to steal Microsoft 365 accounts
  6. RingCentral Data Dump: Immediate Actions and Lessons for Singapore
  7. ShinyHunters Publishes RingCentral Customer Data in …
  8. Ernst Receives Warning, RingCentral Named Leak, GitHub …
  9. RingCentral Data Breach Exposes 16 Million Email Addresses as ShinyHunters Extortion Campaign Raises Fresh Security Concerns + Video – UNDERCODE NEWS
  10. RingCentral, Inc. | Search the Data Breach
  11. ShinyHunters Breach RingCentral, Inc. in Latest …

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply