RingCentral data breach exposed info of 1.6 million accounts

A massive data breach at cloud-based communication platform RingCentral has exposed sensitive information for over 1.6 million accounts, leaving business owners and employees scrambling to assess their security risks. The ShinyHunters extortion group is behind the breach, which was facilitated by a sophisticated social engineering campaign that exploited vulnerabilities in RingCentral’s systems.

RingCentral, used by over 600,000 businesses worldwide for services such as calling, messaging, and voicemail, disclosed the incident on July 28. However, it wasn’t until August 12 that Have I Been Pwned, a data breach notification service, confirmed the severity of the breach after analyzing leaked data from ShinyHunters’ dark web leak site. The stolen information includes names, email addresses, phone numbers, and physical addresses for nearly 1.6 million accounts.

The ShinyHunters group has been linked to several high-profile breaches in recent months, including attacks on hundreds of Salesforce customers, over a dozen Snowflake customers, and various third-party integration providers. The group’s tactics typically involve using social engineering campaigns to gain access to sensitive systems, after which they demand payment from affected companies in exchange for deleting the stolen data.

The breach highlights the ongoing threat posed by sophisticated attackers who can exploit even seemingly secure systems. RingCentral has assured its customers that it has taken remediation efforts to prevent further unauthorized activity and is communicating directly with affected customers. However, the incident serves as a stark reminder of the importance of robust security measures and regular vulnerability assessments for businesses relying on cloud-based services.

The ShinyHunters group’s modus operandi involves using stolen data to extort payment from companies rather than selling it on the dark web or using it for malicious purposes. This approach has raised concerns among cybersecurity experts, who warn that such tactics can create a culture of vulnerability within affected organizations, making them more susceptible to future attacks.

In practical terms, this breach serves as a stark reminder of the need for businesses to prioritize robust security measures and stay vigilant against emerging threats. Companies relying on cloud-based services like RingCentral should ensure they have implemented adequate security controls, including regular backups, multi-factor authentication, and up-to-date software patches. By doing so, they can minimize their exposure to similar attacks in the future.


Source: Bleeping Computer — 2026-08-14