RingCentral, a cloud-based business communications platform, had data on approximately 1.6 million accounts exposed after a ShinyHunters extortion campaign in July 2026.
Loading page…
Loading page…
RingCentral, a cloud-based business communications platform, had data on approximately 1.6 million accounts exposed after a ShinyHunters extortion campaign in July 2026.
According to Have I Been Pwned, in July 2026 the ShinyHunters hacking group targeted RingCentral with a "pay or leak" extortion campaign. When the demand was not met, the group published data they claimed to have obtained from the platform.
RingCentral confirmed the incident in a security bulletin, describing it as affecting a limited portion of its customers. The company stated it was communicating directly with those affected.
Reported by Have I Been Pwned, the published data contained approximately 1.6 million unique email addresses along with names, physical addresses, and phone numbers.
According to RingCentral's disclosure, a subset of its business customers were affected. The breach involved roughly 1.6 million accounts, suggesting the impacted group spans a wide range of RingCentral users.
If you are a RingCentral customer, watch for any direct communication from the company regarding your account. Be alert to phishing attempts, as your name, email, phone number, and address may be in the hands of threat actors. Consider using a unique email address for business communications services going forward, and report any suspicious contact to RingCentral support.