RingCentral
Incident posture
Linked entities
- Victim
- RingCentral
- Threat actors
- 1 actor
- Sources
- 3 sources
Timeline
Summary
RingCentral experienced a breach after a sophisticated social engineering campaign that allowed attackers to access customer data. The ShinyHunters extortion group claimed responsibility, asserting they stole over 600 gigabytes of information including names, email addresses, phone numbers and physical addresses. When the ransom demand was not met, the group released a 280‑gigabyte archive containing the data. Have I Been Pwned later added the leak to its database, noting approximately 1.6 million unique email addresses among the exposed records. The company stated that only a limited subset of customers was affected, that those individuals were notified directly, and that the core platform and services remained operational. An investigation with a third‑party forensic firm found no further unauthorized activity after remediation.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
In July 2026 RingCentral detected unauthorized activity on its systems that it later described as the result of a sophisticated social engineering campaign. Upon detection the company took immediate steps to stop the intrusion and launched an investigation with the assistance of a leading third‑party forensic firm. RingCentral disclosed the incident publicly on July 28, stating that only a limited portion of its customers had been affected and that those individuals were being notified directly. The company emphasized that if a customer was not contacted by RingCentral they were not impacted and that the core platform remained operational without disruption. RingCentral also reported that it had not observed any new unauthorized activity after completing its remediation efforts.
On July 27 the extortion group ShinyHunters posted on its Tor‑based leak site claiming responsibility for the breach and asserting that it had exfiltrated approximately 623 gigabytes of data from RingCentral. The group set a July 30 deadline for the company to pay a ransom or face public release of the stolen information. When RingCentral did not meet the demand, ShinyHunters followed through and published a 280 gigabyte archive containing the alleged data on its leak site. Have I Been Pwned later analyzed the leaked archive and confirmed that it held records for about 1.6 million unique email addresses accompanied by names, physical addresses and phone numbers. The breach information was subsequently added to the Have I Been Pwned database on the Thursday following the leak.
RingCentral maintained that the incident did not affect its core communications platform and that its services continued to operate normally. The company reiterated that customers who had not received a direct notification from RingCentral were not affected by the breach. The exposed personal data included names, email addresses, telephone numbers and mailing addresses, according to the Have I Been Pwned analysis. No evidence was presented in the disclosed reports that the breach had disrupted any of RingCentral’s business phone, messaging, video meeting or AI‑assisted collaboration features.
ShinyHunters told reporters that the initial access was obtained by voice‑phishing an RingCentral employee and tricking the employee into revealing their password. The group also claimed to have conducted similar attacks on hundreds of Salesforce customers, numerous Snowflake environments and various third‑party integration providers, citing a broader campaign of extortion. RingCentral has not independently verified the attackers’ assertions regarding the volume of data stolen or the specific methods used. The company continues to monitor its environment and has stated that no further unauthorized activity has been observed since the remediation steps were taken.
Sources
Sources available to members: 3 sources.