The breach began when RingCentral was targeted by what the company described as a "sophisticated social engineering campaign" . On July 27, 2026, ShinyHunters listed RingCentral on its leak site, claiming to have compromised employee data, user records, and credentials
. The group gave the company until July 30 to respond
.
When RingCentral did not meet the attackers' demands, ShinyHunters followed through on its threat and published the stolen data publicly in a "pay or leak" extortion campaign .
The exposed dataset included approximately 1.6 million unique email addresses . Alongside each email were the associated names, physical addresses, and phone numbers of RingCentral account holders
. ShinyHunters also claimed to have compromised employee data and credentials, though the full scope beyond customer PII has not been detailed in public disclosures
.
The dataset was loaded into Have I Been Pwned on August 13, 2026. HIBP reported that 44% of the email addresses were already in its database from prior breaches .
RingCentral provides cloud-based calling, messaging, and voicemail services to over 600,000 businesses . While the company stated the breach affected only a "limited portion" of its customers, the 1.6 million exposed accounts still represent a significant subset of its user base, and the incident raised concerns about supply-chain risk and third-party vendor security for RingCentral's business customers
.
RingCentral disclosed the breach on July 28, 2026, one day after ShinyHunters listed the company on its leak site . The company stated that upon detection, it "promptly took steps to stop the unauthorized activity" and launched an investigation with the help of a leading third-party forensic firm
. RingCentral reported that it had not seen any new unauthorized activity since taking these remediation steps
.
RingCentral confirmed it was contacting affected customers directly . The company did not meet ShinyHunters' ransom demands, which resulted in the data being published publicly
.
The combination of email addresses, phone numbers, names, and physical addresses creates a high risk of targeted phishing, vishing (voice phishing), social engineering, and identity fraud for affected users . Because the data was published publicly rather than sold privately, attackers and scammers can easily access the information.
The ShinyHunters breach of RingCentral underscores the risk of social engineering attacks against SaaS platforms that handle large volumes of customer PII. Because the attackers followed through with publication after a refused ransom, all affected users should consider themselves at elevated risk for targeted phishing and should treat unsolicited communications referencing RingCentral with heightened scrutiny.
Businesses that rely on RingCentral should also review their third-party vendor security policies and ensure that incident response plans account for the possibility of a cloud vendor's customer data being exposed in a public dump.