Contained Medium impact Data breach Checked 1d ago

ShinyHunters breach exposes 1.6 million RingCentral accounts

The extortion group ShinyHunters stole personal data from cloud communications provider RingCentral in July 2026 by voice-phishing an employee out of a password. RingCentral disclosed the breach on July 28 and said it affected a limited portion of its customers. In mid August the stolen data, including 1.6 million email addresses along with names, physical addresses, and phone numbers, was leaked online and confirmed by the breach notification service Have I Been Pwned.

Started
Jul 1, 2026
Latest activity
Aug 15, 2026
Attributed to
ShinyHuntersConfirmed
Where
United States
Sectors
Technology, Telecom
Scale
one company, about 1.6 million customer accounts

Current status

As of 2026-09-10, no credible new RingCentral update was found after 2026-08-15; later reports only repeated the known leak.

Contained: The attack has been stopped or blocked. Recovery and investigation are still running.

Who is behind it

ShinyHunters claimed the breach themselves on their leak site, and RingCentral confirmed it was hit by a social engineering attack.

Impact

Attackers called an employee and talked them out of a password, then used that access to steal customer contact data. No passwords or financial data have been reported as exposed. RingCentral's service itself was not disrupted.

What to do

RingCentral customers should watch for follow up phishing or vishing calls that reference their real contact details, since that stolen information is now circulating publicly.

Timeline

  1. Aug 15, 2026

    A ShinyHunters spokesperson told reporters the group got in by voice-phishing a RingCentral employee out of their password, with no software exploit involved.

    Containedthenextweb.com
  2. Aug 14, 2026

    Have I Been Pwned confirmed 1.6 million RingCentral accounts, including emails, names, addresses, and phone numbers, had been leaked publicly.

    Containedbleepingcomputer.com
  3. Jul 28, 2026

    RingCentral disclosed it was the target of a sophisticated social engineering campaign affecting a limited portion of customers.

    Containedtheregister.com
  4. Jul 27, 2026

    ShinyHunters posted a extortion claim against RingCentral on its leak site with a deadline to pay by July 30.

    ransomware.live

Sources

Related reports