HomeData BreachesRingCentral Confirms Data Breach Affecting 1.6 Million People After ShinyHunters Extortion Attempt

RingCentral Confirms Data Breach Affecting 1.6 Million People After ShinyHunters Extortion Attempt

RingCentral, a widely used cloud-based communications and contact center platform, has confirmed a data breach that appears to have exposed personal information belonging to roughly 1.6 million people. The company says the incident traces back to a social engineering campaign carried out in July 2026, and that the stolen data was later published online by an extortion group after RingCentral declined to pay a ransom.

Social engineering refers to attacks that manipulate people, rather than software, into handing over access. Instead of exploiting a technical flaw, attackers typically trick an employee through a phone call, phishing message, or impersonation into granting login credentials or system access. SecurityWeek, which first reported the scope of the breach on August 14, said this was the method used against RingCentral.

The group behind the attack has been identified as ShinyHunters, a name that has become familiar in cybersecurity circles as an extortion operation that steals data and then threatens to release it publicly unless a ransom is paid, rather than encrypting systems the way traditional ransomware gangs do. According to SecurityWeek’s reporting, ShinyHunters added RingCentral to its Tor-based leak site in late July, claiming to have obtained 623 gigabytes of stolen data. About a week later, after RingCentral reportedly refused to pay, the group published a 280 gigabyte archive of that data.

The exposed information includes names, addresses, email addresses, and phone numbers. RingCentral has not disclosed an exact number of affected individuals, but outside estimates put the figure at approximately 1.6 million. On Thursday, the breach notification service Have I Been Pwned added the leaked dataset to its records, meaning individuals can now check whether their information was included.

In a statement reported by SecurityWeek, RingCentral said: “Upon detection, we promptly took steps to stop the unauthorized activity and immediately began an investigation with assistance from a leading third-party forensic firm.” The company also said only a limited portion of its customers were affected and that its services “continue to operate without disruption.”

SecurityWeek noted it reached out to RingCentral for further comment and had not received an additional response by the time of publication. No information has emerged suggesting that passwords, payment card numbers, or other highly sensitive financial data were part of the stolen material, though anyone who received the affected communications should remain alert to follow-up phishing attempts that use the leaked contact details to appear more convincing.

Because the stolen data centers on contact information rather than passwords, the most immediate risk to affected individuals is targeted phishing and impersonation attempts rather than direct account takeover. Security researchers generally recommend that people who suspect their information was exposed in a breach like this be cautious of unexpected calls, texts, or emails that reference personal details, since scammers often use leaked data to make fraudulent messages look legitimate.

Source: Ionut Arghire, “1.6 Million Likely Impacted by RingCentral Data Breach,” SecurityWeek, August 14, 2026.

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Most Popular

Recent Comments