Menu
Browse

Cyber Incident Victim: RingCentral

Date

Jul 2026

Location

Status

Unknown

Updated

2026-08-14 20:23

Timeline
Occurred
Jul 2026
Discovered
Undetermined
Disclosed
Aug 2026
Resolved
Pending
Summary

RingCentral reported a data breach resulting from a sophisticated social engineering campaign that exposed personal information of approximately 1.6 million individuals. The company said only a limited subset of its customers were affected and were notified directly, while the core platform remained operational and no further unauthorized activity was observed after remediation efforts with a third‑party forensic firm. The ShinyHunters extortion group claimed to have stolen over 623 gigabytes of data and, after the victim did not meet their demands, released a 280‑gigabyte archive that included names, addresses, phone numbers and about 1.6 million unique email addresses, which were later added to HaveIBeenPwned’s database.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 0 techniques
Threat Actor Type Location
1 actor Available to members Available to members

Description

In July 2026, RingCentral detected unauthorized activity on its systems resulting from a sophisticated social engineering campaign. Upon detection, the company promptly took steps to stop the activity and launched an investigation with assistance from a leading third‑party forensic firm. RingCentral reported that no new unauthorized activity has been observed since the remediation efforts were implemented. The company issued a notice stating that only a limited portion of its customers was affected and that those individuals were notified directly. RingCentral also said that anyone not contacted by them is not affected and that the core platform remained operational without disruption.

Cyber Incident Image

The ShinyHunters extortion group added RingCentral to its Tor‑based leak site in late July, claiming to have stolen over 623 gigabytes of data. When RingCentral did not meet the extortion demands, ShinyHunters published a 280‑gigabyte archive of the alleged stolen data roughly a week later. HaveIBeenPwned added the leaked information to its database on Thursday, noting that the archive contains approximately 1.6 million unique email addresses accompanied by names, addresses, and phone numbers. RingCentral has not confirmed the attackers’ claims or the exact number of potentially impacted individuals. The exposed personal data includes email addresses, physical addresses, and telephone numbers associated with the affected individuals.

RingCentral describes itself as a cloud‑based provider of unified communications and contact center solutions. Its platform offers business phone service, team messaging, video meetings, and AI‑assisted tools for employee collaboration and customer interactions. The company has stated that it began an investigation with a third‑party forensic firm and observed no new unauthorized activity after remediation. SecurityWeek emailed RingCentral for a statement on the matter and said it would update its coverage if a response is received. As of the article’s publication, no further unauthorized activity has been reported by RingCentral.

Sources
Sources available to members
2 sources