RingCentral Data Breach Exposes 1.6 Million Accounts

RingCentral Data Breach Exposes 1.6 Million Accounts

First seen 14 Aug 2026, 11:53 UTC Bleepingcomputerhaveibeenpwned.com 75% similarity 68.0

Article Content

Browse articles
ThreatCluster

In July 2026, RingCentral suffered a data breach affecting 1.6 million accounts, attributed to the ShinyHunters extortion group. The breach involved a sophisticated social engineering attack that compromised the company's systems. RingCentral disclosed the incident on July 28, stating that the affected data included names, email addresses, phone numbers, and physical addresses. The ShinyHunters group claimed responsibility and leaked 280GB of data on their dark web site after RingCentral refused to pay a ransom. The company has communicated directly with affected customers and confirmed that the core platform remains operational. No specific details on the attack vector have been provided, but the incident highlights ongoing vulnerabilities in cloud-based services. Have I Been Pwned confirmed the breach's impact by analyzing the leaked data.

Key Points: • 1.6 million RingCentral accounts were compromised due to a social engineering attack. • ShinyHunters extortion group claimed responsibility and leaked data after a ransom demand. • RingCentral confirmed that core services remain operational and affected customers are being notified.

ThreatCluster AI How this analysis works

Timeline

2026-07-27
ShinyHunters claims responsibility for breach
The group announced they had stolen data from RingCentral, including 623GB of information.
BleepingComputer
2026-07-28
RingCentral discloses data breach
RingCentral announced the breach affecting a limited portion of its customers and confirmed ongoing communication with those impacted.
BleepingComputer
2026-08-14
Data confirmed by Have I Been Pwned
The data breach was confirmed to contain records for 1.6 million accounts, including personal information.
haveibeenpwned.com

Community

Browse all →