Data Breaches

1.6 Million Likely Impacted by RingCentral Data Breach

The hackers published the allegedly stolen information, including names, addresses, email addresses, and phone numbers.

RingCentral

The personal information of 1.6 million individuals appears to have been stolen from the widely used business communications platform RingCentral by a notorious extortion group.

The incident occurred in July and was the result of a “sophisticated social engineering campaign”, RingCentral said in a notice on its website.

“Upon detection, we promptly took steps to stop the unauthorized activity and immediately began an investigation with assistance from a leading third-party forensic firm. We have not seen any new unauthorized activity since taking these remediation efforts,” the company said.

According to RingCentral, only a limited portion of its customers was affected by the attack, and those individuals were notified directly.

“If you are not contacted by RingCentral, you are not affected. This incident did not impact the core RingCentral platform, and our services continue to operate without disruption,” it said.

While RingCentral did not name the attackers, the ShinyHunters extortion group added the company to its Tor-based leak site in late July, claiming it stole over 623 gigabytes of data.

Advertisement. Scroll to continue reading.

Roughly a week later, as RingCentral did not succumb to the extortionists’ demands, ShinyHunters published a 280GB archive containing the data allegedly stolen from the company.

On Thursday, data breach reporting site HaveIBeenPwned added the leaked information to its database, saying that it includes approximately 1.6 million unique email addresses, accompanied by names, addresses, and phone numbers.

RingCentral hacked by ShinyHunters

RingCentral has yet to confirm the attackers’ claims and the number of potentially impacted individuals. SecurityWeek has emailed RingCentral for a statement on the matter and will update this article if the company responds.

RingCentral is a cloud-based provider of unified communications and contact center solutions. Its platform delivers business phone, team messaging, video meetings, and AI-assisted tools for employee collaboration and customer interactions.

Related: 14,000 Trezor Customers Impacted by Data Breach at ShipMonk

Related: AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions

Related: River Bank Says Hackers Deleted Data Stolen in Ransomware Attack

Related: Brinks Home Discloses Data Breach as Hackers Leak Files

Related Content

Data Breaches

The root cause of the incident is believed to be a compromised AWS access key that was exposed in publicly available JavaScript build artifacts.

Data Breaches

Hackers stole the customers’ shipping information, including names, addresses, email addresses, and phone numbers.

Cybercrime

Affecting European contract logistics operations at eight Ceva warehouses, the incident caused shipment delays for multiple customers.

Data Breaches

Using social engineering, a threat actor accessed the computers of three employees and exfiltrated data from them.

Data Breaches

Hackers stole personal, medical, and health insurance information from a company’s data center.

Data Breaches

Hackers stole personal information, medical records, and financial information from the organization’s server.

Data Breaches

An extortion group stole personal, financial, and medical information from the hospital’s network.

Data Breaches

The bank holding company was hacked in June, but the investigation into the incident continues.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version