Breaking
Cyber CrimeDeveloping Story

RingCentral Breach Exposes 1.6M Accounts

ShinyHunters leaks data from 1.6 million RingCentral accounts after July hack.

··3 hours ago·3 min read
black and red laptop computer
Photo by FlyD on Unsplash

ShinyHunters, an extortion group known for a string of high-profile data thefts, has leaked a trove of personal information belonging to 1.6 million RingCentral accounts. The disclosure, confirmed by the data breach notification service Have I Been Pwned, follows a July intrusion that the company has described as a "sophisticated social engineering campaign."

RingCentral, a cloud-based collaboration platform used by more than 600,000 businesses for calling, messaging, and voicemail, disclosed the incident on July 28. While the company has not officially attributed the attack to ShinyHunters, the group claimed responsibility on July 27, saying it had stolen 623GB of data. After RingCentral declined to pay a ransom, the cybercriminals released a compressed archive of 280GB on their dark web leak site.

A Confirmed Data Dump

Have I Been Pwned (HIBP) analyzed the leaked files and confirmed the link to RingCentral. The breach notification service reported that the data contains records for 1.6 million accounts, including names, email addresses, phone numbers, and physical addresses.

"In July 2026, the cloud-based business communications platform RingCentral was the target of a ShinyHunters 'pay or leak' extortion campaign," HIBP stated. The reference to 2026 appears to be a typographical error, as the incident occurred in July of the current year.

Company Response

In a security bulletin, RingCentral outlined its response. "We have not seen any new unauthorized activity since taking these remediation efforts. To date, this incident has affected data for a limited portion of RingCentral customers, and we are communicating with affected customers directly," the company noted. It added, "If you are not contacted by RingCentral, you are not affected. This incident did not impact the core RingCentral platform, and our services continue to operate without disruption."

RingCentral has not yet disclosed the exact method of intrusion, nor has it publicly attributed the attack to a specific threat actor. A spokesperson did not immediately respond to requests for comment from BleepingComputer.

ShinyHunters' Expanding Trail

The extortion group has been linked to numerous breaches over the past year. According to reports, ShinyHunters has claimed attacks on hundreds of Salesforce customers, alleging the theft of over 1.5 billion records in campaigns dubbed Salesloft Drift and Salesforce Aura. The group has also been associated with breaches at more than a dozen Snowflake customers, as well as various third-party integration providers.

Most recently, ShinyHunters claimed responsibility for a series of breaches affecting over 100 organizations, exploiting a zero-day flaw in Oracle PeopleSoft. These incidents highlight the group's broad targeting of cloud-based services and their supply chains.

What Data Was Exposed

The leaked records include sensitive personal identifiers. For affected users, this could mean an elevated risk of phishing, identity theft, and other social engineering attacks. The inclusion of physical addresses, alongside emails and phone numbers, provides a more complete profile for malicious actors to exploit.

Have I Been Pwned allows individuals to check if their email address appears in the breach, offering a way for users to assess their exposure.

Implications for Businesses

For RingCentral's customer base, which includes over 600,000 businesses, the breach raises concerns about supply chain security. The platform's deep integration into organizational communications means that compromised accounts could potentially serve as a foothold for further attacks on business networks.

The incident also underscores the persistent threat posed by extortion groups who target cloud service providers. As these providers aggregate vast amounts of personal and corporate data, they become attractive targets for cybercriminals seeking maximum impact.

Why It Matters

This breach serves as a stark reminder that even established cloud platforms with strong security postures can fall victim to sophisticated social engineering. The fact that ShinyHunters was able to exfiltrate and leak data despite RingCentral's remediation efforts suggests that the initial compromise went undetected for some time.

For businesses relying on RingCentral, this could mean re-evaluating their own security dependencies and ensuring that they have contingency plans in place. The incident also highlights the importance of monitoring for signs of credential compromise and being vigilant against phishing attempts that may increase following such data leaks. While RingCentral asserts that its core platform remains operational, the long-term reputational impact and potential for follow-on attacks should not be underestimated.

#ringcentral#shinyhunters#data breach#extortion#have i been pwned

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories