RingCentral says social-engineering breach exposed data from 1.6 million customer accounts as ShinyHunters leaked stolen files

RingCentral customer data from about 1.6 million accounts was exposed after attackers breached the company in July 2026. RingCentral said the intrusion followed a sophisticated social-engineering campaign, and Have I Been Pwned said leaked data tied to the ShinyHunters extortion claim includes names, email addresses, phone numbers, and physical addresses. The gang reportedly stole 623GB and later leaked about 280GB after RingCentral did not pay.
Why it matters: This affects a major business communications provider used by hundreds of thousands of organizations, so exposed contact data could fuel phishing, vishing, and impersonation attacks. Affected customers should watch for targeted scams, review RingCentral-related access logs, and reset or harden accounts if notified.

Sources

1.6M RingCentral accounts' data dumped after ShinyHunters extortion attack
2026.08.14 98% relevant
This article is a direct follow-up on the same RingCentral breach, adding that Have I Been Pwned counted about 1.6 million unique email addresses in the leaked data and confirming ShinyHunters followed through on its extortion threat by publishing customer details online after the July 30 deadline passed.
RingCentral data breach exposed info of 1.6 million accounts
Sergiu Gatlan 2026.08.14 100% relevant
This article establishes the breach’s verified scale and exposed data types for the July 2026 RingCentral intrusion tied to social engineering and claimed by ShinyHunters.
1.6 Million Likely Impacted by RingCentral Data Breach
Ionut Arghire 2026.08.14 99% relevant
This article is a direct update on the same July 2026 RingCentral breach, adding that Have I Been Pwned ingested the leaked data and estimating about 1.6 million unique email addresses were exposed along with names, addresses, and phone numbers.
← Back to all stories