RingCentral Data Breach: 1.6 Million Accounts Exposed – What You Need to Know
A data breach at RingCentral exposed information from 1.6 million user accounts following a cyberattack attributed to the ShinyHunters extortion group, according to reports.
Breach Details and Timeline
The incident, disclosed by the data breach tracking service Have I Been Pwned, involved the unauthorized access of personal data from 1.6 million RingCentral accounts after the company’s systems were compromised in July. RingCentral, a cloud-based communication platform utilized by over 600,000 businesses, reported the breach on July 28. The company described the attack as a “sophisticated social engineering campaign” and stated that no further unauthorized activity had been detected since implementing remediation measures.
ShinyHunters’ Role and Claims
The ShinyHunters group claimed responsibility for the attack on July 27, asserting that they had exfiltrated 623GB of data from RingCentral’s systems. After the company refused to pay a ransom to prevent the data’s release, the group published a 280GB compressed archive of files on a dark web leak site. Have I Been Pwned confirmed the authenticity of the leaked data, which included personal details such as names, addresses, phone numbers, and physical locations for 1.6 million accounts.
Broader Implications and Previous Attacks
The breach occurred amid broader activity by ShinyHunters, which has previously targeted Salesforce customers, Snowflake clients, and third-party integration providers. The group also claimed responsibility for recent breaches exploiting an Oracle PeopleSoft zero-day vulnerability, affecting over 100 organizations. RingCentral has not yet disclosed the specific method used by attackers to gain access to its systems. However, ShinyHunters has previously claimed to have stolen over 1.5 billion records from Salesforce, Salesloft, and Drift platforms.
Security Vulnerabilities and Industry Response
The breach highlights vulnerabilities in credential-based attacks, as 37% of malicious activities are blocked when attackers possess valid credentials, according to the Blue Report 2026. The report analyzed 338 million security simulations across customer environments to evaluate defensive measures.
The incident underscores the growing threat of extortion groups leveraging social engineering and zero-day exploits to compromise enterprise systems. RingCentral advised affected users to await direct communication from the company, stating that those not contacted were not impacted.
RingCentral’s Response and Recommendations
The breach adds to a series of high-profile leaks linked to ShinyHunters, raising concerns about the security of cloud-based collaboration tools and third-party service integrations. RingCentral emphasized that the breach affected only a “limited portion” of its customer base and that core services remained operational without disruption.
