BusinessCybersecurityNewswireTechnologyWhat's Buzzing

RingCentral breach exposes data of 1.6M accounts

Originally published on: August 15, 2026
▼ Summary

– ShinyHunters stole personal data from 1.6 million RingCentral accounts, including names, emails, phone numbers, and addresses, as confirmed by Have I Been Pwned.
– RingCentral disclosed the breach on July 28, attributing it to a “sophisticated social engineering campaign,” but stated the core platform was unaffected and services continued without disruption.
– ShinyHunters claimed responsibility on July 27 for stealing 623GB of data and leaked a 280GB archive after RingCentral refused to pay a ransom.
– RingCentral has not officially attributed the breach to ShinyHunters or provided details on how attackers gained access.
– ShinyHunters has a history of major breaches, including hundreds of Salesforce customers, over a dozen Snowflake clients, and recent attacks exploiting an Oracle PeopleSoft zero-day flaw.

The ShinyHunters extortion group is claiming responsibility for a data breach that exposed personal information belonging to 1.6 million RingCentral accounts, according to the data breach notification service Have I Been Pwned.

RingCentral provides cloud-based collaboration and communication tools, including calling, messaging, and voicemail, to more than 600,000 businesses.

The company first disclosed the security incident on July 28, stating that its systems had been breached through what it characterized as a “sophisticated social engineering campaign.”

“We have not seen any new unauthorized activity since taking these remediation efforts. To date, this incident has affected data for a limited portion of RingCentral customers, and we are communicating with affected customers directly,” the company said in its disclosure.

“If you are not contacted by RingCentral, you are not affected. This incident did not impact the core RingCentral platform, and our services continue to operate without disruption.”

RingCentral has not officially attributed the attack to any specific threat actor, nor has it released additional technical details about how the intrusion occurred. However, on July 27, the ShinyHunters extortion gang claimed they had stolen 623GB of data from the company.

After RingCentral declined to pay a ransom for the deletion of the stolen information, the cybercrime group published a compressed archive containing roughly 280GB of files on their dark web leak site.

A RingCentral spokesperson did not immediately respond to BleepingComputer’s request to confirm ShinyHunters’ claims. However, Have I Been Pwned analyzed the leaked data and confirmed the connection on Thursday, stating that the archive contained records for 1.6 million accounts, including names, email addresses, phone numbers, and physical addresses.

“In July 2026, the cloud-based business communications platform RingCentral was the target of a ShinyHunters ‘pay or leak’ extortion campaign,” the notification service stated.

RingCentral has not yet explained precisely how the attackers gained access to its systems. ShinyHunters, meanwhile, has claimed breaches at hundreds of Salesforce customers over the past year, alleging the theft of over 1.5 billion records through campaigns targeting Salesloft Drift and Salesforce Aura.

The extortion group has also been linked to security incidents at more than a dozen Snowflake customers, in addition to various other third-party integration providers.

Most recently, ShinyHunters took credit for a fresh wave of attacks against over 100 organizations, exploiting a zero-day vulnerability in Oracle PeopleSoft to carry out data-theft operations.

(Source: BleepingComputer)

Topics

data breach 98% extortion group 96% personal data theft 94% social engineering 89% ransom payment 86% cloud communications 83% breach notification 81% cybercrime group 79% dark web leak 76% security incident response 74%