ShinyHunters breach exposes 1.6 million RingCentral accounts
The extortion group ShinyHunters stole personal data from cloud communications provider RingCentral in July 2026 by voice-phishing an employee out of a password. RingCentral disclosed the breach on July 28 and said it affected a limited portion of its customers. In mid August the stolen data, including 1.6 million email addresses along with names, physical addresses, and phone numbers, was leaked online and confirmed by the breach notification service Have I Been Pwned.
- Started
- Jul 1, 2026
- Latest activity
- Aug 15, 2026
- Attributed to
- ShinyHuntersConfirmed
- Where
- United States
- Sectors
- Technology, Telecom
- Scale
- one company, about 1.6 million customer accounts
Current status
As of 2026-09-10, no credible new RingCentral update was found after 2026-08-15; later reports only repeated the known leak.
Contained: The attack has been stopped or blocked. Recovery and investigation are still running.
Who is behind it
ShinyHunters claimed the breach themselves on their leak site, and RingCentral confirmed it was hit by a social engineering attack.
Impact
Attackers called an employee and talked them out of a password, then used that access to steal customer contact data. No passwords or financial data have been reported as exposed. RingCentral's service itself was not disrupted.
What to do
RingCentral customers should watch for follow up phishing or vishing calls that reference their real contact details, since that stolen information is now circulating publicly.
Timeline
-
Aug 15, 2026
A ShinyHunters spokesperson told reporters the group got in by voice-phishing a RingCentral employee out of their password, with no software exploit involved.
Containedthenextweb.com -
Aug 14, 2026
Have I Been Pwned confirmed 1.6 million RingCentral accounts, including emails, names, addresses, and phone numbers, had been leaked publicly.
Containedbleepingcomputer.com -
Jul 28, 2026
RingCentral disclosed it was the target of a sophisticated social engineering campaign affecting a limited portion of customers.
Containedtheregister.com -
Jul 27, 2026
ShinyHunters posted a extortion claim against RingCentral on its leak site with a deadline to pay by July 30.
ransomware.live
Sources
- RingCentral data breach exposed info of 1.6 million accounts Bleeping Computer Aug 14, 2026
- 1.6M RingCentral accounts' data dumped after ShinyHunters extortion attack The Register Aug 14, 2026
- RingCentral data breach by ShinyHunters attackers SC World Aug 3, 2026
- Shinyhunters ransomware claims RingCentral, Inc. ransomware.live Jul 27, 2026
- A phone company just lost 1.6 million records to a phone call The Next Web Aug 15, 2026
- RingCentral Confirms Data Leak Hitting 1.6 Million Accounts Android Headlines Aug 14, 2026
Related reports
- Shinyhunters ransomware claims RingCentral, Inc. Jul 27, 2026