RingCentral data breach (ShinyHunters)
After RingCentral refused to pay an extortion demand, the ShinyHunters group dumped a data archive exposing names, email addresses, phone numbers and physical addresses linked to roughly 1.6 million customer accounts, stolen via a social-engineering intrusion earlier in the summer.
- Victim
- RingCentral, Inc.
- records
- 1.6M
- users
- 1.6M
On 14 August 2026, the extortion group ShinyHunters published a large data archive exposing information tied to roughly 1.6 million accounts of RingCentral, Inc. β the U.S. cloud-communications and VoIP provider β after the company refused to pay a ransom. The data had been stolen weeks earlier through a social-engineering intrusion, and its release turned a quiet July disclosure into one of the more widely reported breaches of the summer.
RingCentral said the exposed fields were limited to names, email addresses, phone numbers and physical addresses; there is no indication that the core RingCentral platform, call data or service availability were affected.
What happened
According to RingCentral and to security reporting, ShinyHunters gained access to the company's systems in July 2026 via a social-engineering attack and exfiltrated approximately 623 GB of data. On 27 July 2026, the group claimed the intrusion and demanded payment. RingCentral disclosed the unauthorised activity the following day, brought in a third-party forensic firm, and stressed that its production communications platform was not compromised.
When RingCentral declined to pay, ShinyHunters escalated. On 13 August 2026, Have I Been Pwned added the breach to its database after confirming the leaked records, and on 14 August the group published a roughly 280 GB archive covering about 1.6 million accounts. The wider release is what fixed the incident's scale in public reporting.
Impact
- Personal data β names, emails, phone numbers and physical addresses β for approximately 1.6 million accounts was exposed and ultimately leaked.
- No evidence that seed data such as passwords, payment details, or call content was taken; RingCentral's core service was not disrupted.
- Affected individuals face heightened phishing and social-engineering risk, particularly because contact details were paired with the RingCentral brand.
Why it matters
The RingCentral case is another entry in ShinyHunters' 2026 run of social-engineering-led extortion against enterprise SaaS and communications vendors. It reinforces two recurring lessons: that human-targeted intrusion β rather than a software exploit β remains a leading path into well-defended cloud providers, and that refusing to pay does not prevent data exposure once the attacker has already exfiltrated the records. For a communications vendor whose customers are themselves businesses, the leaked contact directory is a ready-made target list for downstream phishing.
Timeline
ShinyHunters gains access to RingCentral systems through a social-engineering attack and exfiltrates roughly 623 GB of data.
ShinyHunters claims responsibility for the intrusion and issues an extortion demand.
RingCentral discloses the unauthorised activity, engages a third-party forensic firm, and says its core platform and service availability were not affected.
Have I Been Pwned adds the breach to its database after confirming the leaked data.
After RingCentral declines to pay, ShinyHunters publishes a ~280 GB archive covering roughly 1.6 million accounts, prompting wide reporting of the breach's scope.
Sources
- theregister.comhttps://www.theregister.com/cyber-crime/2026/08/14/16m-ringcentral-accounts-data-dumped-after-shinyhunters-extortion-attack/5288003
- bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/ringcentral-data-breach-exposed-info-of-16-million-accounts/
- securityweek.comhttps://www.securityweek.com/1-6-million-likely-impacted-by-ringcentral-data-breach/
- haveibeenpwned.comhttps://haveibeenpwned.com/Breach/RingCentral