1.6 Million Likely Impacted by RingCentral Data Breach

A massive data breach has hit RingCentral, a popular business communications platform used by over 1.6 million individuals, according to security researchers who have added the stolen information to their database. The attack, carried out by a notorious extortion group called ShinyHunters, involves the theft of sensitive personal data, including email addresses, names, addresses, and phone numbers.

RingCentral, which offers cloud-based unified communications and contact center solutions, confirmed that only a limited portion of its customers were affected by the breach. The company stated that it had taken immediate action to stop the unauthorized activity and was working with a third-party forensic firm to investigate the incident. However, the extent of the damage is still unclear.

According to RingCentral, the attackers used a “sophisticated social engineering campaign” to gain access to its systems. Social engineering attacks involve tricking employees into divulging sensitive information or gaining unauthorized access to systems. This type of attack can be particularly challenging to detect and prevent, as it often involves human error rather than technical vulnerabilities.

ShinyHunters claimed to have stolen over 623 gigabytes of data from RingCentral, including emails, contacts, and other business communications. The attackers added the company’s name to their Tor-based leak site in late July and published a 280GB archive containing the allegedly stolen data roughly a week later. However, it remains unclear whether all of the information is accurate or if some of it may have been fabricated.

The breach has significant implications for individuals who use RingCentral for business communications. While the company claims that its core platform was not impacted and services continue to operate without disruption, users should be vigilant about monitoring their accounts for suspicious activity. Those who have received notifications from RingCentral regarding the breach should take immediate action to protect themselves by changing passwords, monitoring credit reports, and being cautious of phishing emails.

The incident serves as a reminder of the importance of robust cybersecurity measures in protecting against social engineering attacks. Businesses and individuals alike should prioritize employee training on cybersecurity best practices, implement robust security protocols, and regularly update software to prevent similar breaches from occurring. By staying informed about emerging threats and taking proactive steps to secure systems, we can mitigate the risks associated with these types of attacks.

In practical terms, users who may be impacted by this breach should take a few simple steps to protect themselves: change their passwords, monitor their credit reports for suspicious activity, and be cautious of unsolicited emails or phone calls. By taking these precautions, individuals can minimize the risk of falling victim to phishing scams or other types of cyber attacks that may exploit the stolen data.


Source: SecurityWeek — 2026-08-14