The ShinyHunters extortion group allegedly stole personal information belonging to 1.6 million RingCentral accounts after compromising the company in July, according to Have I Been Pwned, a data breach notification service.
RingCentral is a cloud-based business communications and collaboration platform used by more than 600,000 organizations for voice calling, messaging, video meetings, and voicemail services.
RingCentral disclosed the cybersecurity incident on July 28, stating that its systems had been compromised in what the company described as a “sophisticated social engineering campaign.”
“Since performing these remediation efforts, we have not observed any new fraudulent activity. To date, this incident has impacted data for some RingCentral customers, and we are in direct contact with affected customers,” RingCentral said.
“If you have not heard from RingCentral, you are not affected. This incident does not impact RingCentral’s core platform, and our services continue to operate without interruption.”
RingCentral has not attributed the breach to a specific threat actor or hacking group and has not released technical details about how the attackers gained access. However, the ShinyHunters extortion group claimed responsibility on July 27 and alleged that it had stolen 623 GB of data.

After RingCentral allegedly refused to pay a ransom in exchange for deleting the stolen information, the cybercriminal group published a compressed archive containing approximately 280 GB of files on a dark web data leak site.
When BleepingComputer contacted RingCentral for comment on ShinyHunters’ claims, a company spokesperson did not immediately respond. Have I Been Pwned later confirmed the breach after analyzing the leaked data. The service said the exposed information included records for 1.6 million accounts, containing names, email addresses, phone numbers, and physical addresses.
“In July 2026, cloud-based business communications platform RingCentral became the target of ShinyHunters’ ‘pay or be leaked’ extortion campaign,” Have I Been Pwned stated.
RingCentral has not disclosed precisely how the threat actor accessed its systems. ShinyHunters, however, claims to have compromised hundreds of Salesforce customers during the past year and says it stole more than 1.5 billion records in attacks involving Salesloft, Drift, and Salesforce Aura.
The extortion group has also been linked to data breaches affecting more than a dozen Snowflake customers, as well as attacks against several third-party integration providers.
More recently, ShinyHunters claimed responsibility for a new wave of breaches involving more than 100 organizations after attackers allegedly exploited a zero-day vulnerability in Oracle PeopleSoft.
The overall prevention score can obscure what happens after an attacker gains initial access. When threat actors use valid credentials, the effectiveness of security defenses can drop sharply.
Blue Report 2026 measures defensive techniques across technologies using 338 million simulations conducted in customer production environments.
Source: www.bleepingcomputer.com




