A massive data breach at RingCentral, a leading provider of business communications and collaboration tools, has exposed the personal information of approximately 1.6 million individuals. The incident, which occurred in July, was carried out by a notorious extortion group known as ShinyHunters.
RingCentral, which offers cloud-based unified communications, contact center solutions, and AI-assisted tools for employee collaboration and customer interactions, says that only a limited portion of its customers were affected by the attack. The company claims to have taken swift action upon detection, stopping unauthorized activity and launching an investigation with the assistance of a third-party forensic firm.
However, ShinyHunters has publicly claimed responsibility for the breach, publishing a 280GB archive on their Tor-based leak site in late July. This archive allegedly contains over 623 gigabytes of stolen data, including names, addresses, phone numbers, and email addresses. While RingCentral has not confirmed the attackers’ claims, data breach reporting site HaveIBeenPwned has added the leaked information to its database.
According to security experts, ShinyHunters is a well-known extortion group that uses social engineering tactics to gain access to sensitive systems. In this case, it appears that they launched a sophisticated campaign against RingCentral, exploiting vulnerabilities in their internal processes. The attackers typically demand ransom payments from affected organizations, but RingCentral has refused to pay, leading ShinyHunters to publish the stolen data.
This incident highlights the ongoing threat of data breaches and extortion attacks, which can have severe consequences for individuals and businesses alike. With the rise of cloud-based services and AI-assisted tools, the risk of sensitive information being compromised continues to grow. Organizations must prioritize robust security measures, including regular backups, monitoring, and incident response planning, to mitigate these risks.
RingCentral’s customers who may be affected by this breach are advised to monitor their accounts closely for any suspicious activity and to change their passwords immediately. Additionally, individuals whose email addresses or other contact information has been compromised should take steps to protect themselves from potential phishing attacks or identity theft. By staying informed and taking proactive measures, we can all do our part in minimizing the impact of these types of incidents.
For those affected by this breach, it’s essential to remain vigilant and monitor their personal and business accounts closely. Regularly reviewing your credit reports, keeping an eye on financial statements, and being cautious when receiving unsolicited emails or calls can help prevent further harm. Remember, security is a shared responsibility – staying informed and taking proactive measures can make all the difference in protecting yourself and your organization from these types of threats.
Source: SecurityWeek — 2026-08-14