Skip to content
NetarxImpact Database
Vishing (Voice Phishing)UnknownConfirmed

RingCentral data on 1.6M accounts leaked after social engineering campaign

RingCentral · Technology · United States · July 2026

People or records affected
1,600,000
1.6M as reported

What happened

Cloud communications provider RingCentral attributed a July 2026 breach to a sophisticated social engineering campaign. ShinyHunters claimed responsibility on 27 July and RingCentral disclosed the incident on 28 July. The group said it had taken 623GB of data and, after the company refused to pay, published a 280GB archive on its leak site. Have I Been Pwned counted 1.6 million affected accounts, with names, email addresses, phone numbers and physical addresses exposed. Services were not disrupted.

How the deception worked

RingCentral has published only that the entry point was a sophisticated social engineering campaign rather than a technical vulnerability, consistent with the ShinyHunters pattern of calling employees while posing as internal IT and capturing single sign-on credentials and session tokens through a real-time lookalike login portal. With an authenticated identity the crew reached customer account data and exfiltrated it at volume before opening extortion negotiations, offering destruction of the data in exchange for payment. RingCentral said no unauthorised activity followed remediation.

The control that would have caught it· our reading, not a claim from the sources

Phishing-resistant MFA and session binding to managed devices are the controls that stop a persuaded employee from becoming an authenticated attacker session.

Sources (2)

  1. RingCentral data breach exposed info of 1.6 million accounts
    BleepingComputer·bleepingcomputer.comOpen ↗
  2. 1.6 Million Likely Impacted by RingCentral Data Breach
    SecurityWeek·securityweek.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.