What happened
Cloud communications provider RingCentral attributed a July 2026 breach to a sophisticated social engineering campaign. ShinyHunters claimed responsibility on 27 July and RingCentral disclosed the incident on 28 July. The group said it had taken 623GB of data and, after the company refused to pay, published a 280GB archive on its leak site. Have I Been Pwned counted 1.6 million affected accounts, with names, email addresses, phone numbers and physical addresses exposed. Services were not disrupted.
How the deception worked
RingCentral has published only that the entry point was a sophisticated social engineering campaign rather than a technical vulnerability, consistent with the ShinyHunters pattern of calling employees while posing as internal IT and capturing single sign-on credentials and session tokens through a real-time lookalike login portal. With an authenticated identity the crew reached customer account data and exfiltrated it at volume before opening extortion negotiations, offering destruction of the data in exchange for payment. RingCentral said no unauthorised activity followed remediation.
The control that would have caught it· our reading, not a claim from the sources
Phishing-resistant MFA and session binding to managed devices are the controls that stop a persuaded employee from becoming an authenticated attacker session.
Sources (2)
- RingCentral data breach exposed info of 1.6 million accountsBleepingComputer·bleepingcomputer.comOpen ↗
- 1.6 Million Likely Impacted by RingCentral Data BreachSecurityWeek·securityweek.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.