RingCentral data breach exposed info of 1.6 million accounts

A massive data breach at RingCentral, a popular cloud-based collaboration and communication platform used by over 600,000 businesses, has exposed the personal information of an astonishing 1.6 million accounts. The ShinyHunters extortion group is behind the hack, which was made possible through a “sophisticated social engineering campaign” that compromised RingCentral’s systems in July.

The breach affects a significant portion of RingCentral customers, who may have had their names, email addresses, phone numbers, and physical addresses stolen. While RingCentral has assured its users that the core platform remains unaffected, the incident highlights the growing threat of cyberattacks on cloud-based services. The company disclosed the breach on July 28, but it wasn’t until this week that Have I Been Pwned confirmed the extent of the damage.

RingCentral’s systems were compromised through a social engineering campaign, which is essentially a type of phishing attack designed to trick employees into divulging sensitive information or handing over access credentials. Once attackers have valid login details, they can gain unrestricted access to an organization’s network and data. This incident serves as a stark reminder that even the most robust security measures can be breached through human error.

The ShinyHunters extortion group has been linked to several high-profile breaches in recent months, including attacks on Salesforce customers, Snowflake users, and other third-party integration providers. The gang’s modus operandi is to extort money from affected companies by threatening to leak sensitive data unless they pay up. RingCentral refused to cave in to ShinyHunters’ demands, leading the group to release a compressed archive containing 280GB of stolen files on their dark web leak site.

While it’s unclear exactly how the attackers gained access to RingCentral’s systems, the incident has raised concerns about the security of cloud-based services. As more businesses shift their operations online, they must prioritize robust security measures to protect against such threats. The breach also underscores the importance of user education and awareness in preventing social engineering attacks.

In light of this breach, it’s essential for users to remain vigilant and monitor their accounts closely. If you’re a RingCentral customer who hasn’t been contacted by the company directly, you may want to consider taking proactive steps to protect your data. This includes updating your login credentials, enabling two-factor authentication, and monitoring your account activity regularly.

Ultimately, this breach serves as a wake-up call for organizations to reassess their security posture and invest in robust defense measures that can withstand even the most sophisticated attacks. By prioritizing cybersecurity and educating users about online threats, we can work together to prevent such incidents from occurring in the future.


Source: Bleeping Computer — 2026-08-14