RingCentral Data Breach Exposes Personal Information of 1.6 Million Accounts
RingCentral, a cloud-based business communications platform used by more than 600,000 companies worldwide, disclosed on July 28, 2026 that it had suffered a security incident after falling victim to what it described as a “sophisticated social engineering campaign.” The extortion group ShinyHunters claimed responsibility for the breach and said it had exfiltrated roughly 623GB of data from the company’s systems.
According to the breach notification service Have I Been Pwned, which analyzed a portion of the data published on ShinyHunters’ dark web leak site after RingCentral reportedly declined to pay a ransom, the stolen records span 1.6 million accounts and include customer names, email addresses, phone numbers and physical addresses. RingCentral has said the intrusion did not affect its core platform, that services continued operating without disruption, and that it is notifying affected customers directly rather than issuing a blanket public warning.
The incident adds RingCentral to a growing list of organizations targeted by ShinyHunters, a group linked to a string of extortion campaigns over the past year against Salesforce customers, users of the Salesloft Drift integration, Snowflake customers, and, most recently, organizations running Oracle PeopleSoft systems compromised via a zero-day vulnerability. Across these campaigns the group has claimed to have stolen well over a billion records combined, underscoring the scale of the ongoing wave of attacks against SaaS platforms and third-party integrations.