Cloud-based business communications provider RingCentral suffered a data breach in July 2026 after falling victim to an extortion campaign by the cybercrime group ShinyHunters. When RingCentral apparently refused to pay the ransom demand, ShinyHunters published stolen customer data affecting approximately 1.6 million accounts.
ShinyHunters has established a pattern of targeting major technology companies with pay-or-leak extortion schemes, where they steal data and threaten public disclosure unless the victim organization pays a ransom. RingCentral, which provides cloud-based phone systems, video conferencing, and messaging services to businesses worldwide, became the latest victim of this criminal operation.
The leaked dataset contains 1.6 million unique email addresses along with associated customer names, physical addresses, and phone numbers. While the exposed information does not include passwords or financial data according to available reports, the combination of contact details and physical addresses creates significant risks for affected individuals. This type of data can be used for targeted phishing campaigns, identity theft attempts, and social engineering attacks.
RingCentral has acknowledged the incident in a public disclosure notice, stating that it affected a limited portion of its customer base. The company has not specified what percentage of its total users were impacted or provided details about how ShinyHunters gained access to its systems. The breach raises concerns about the security practices of enterprise communication platforms that handle sensitive business contact information.
Affected customers should remain vigilant against phishing attempts and unsolicited communications that reference their personal information. Organizations using RingCentral should verify whether their accounts were compromised by checking with the service directly or monitoring breach notification databases. Security teams should remind employees to be suspicious of emails or calls that appear to have insider knowledge of their contact details, as this stolen data may be used in targeted social engineering campaigns for months or years to come.
Source: https://haveibeenpwned.com/Breach/RingCentral


