Skip to content
Cyber Security Firms
ConfirmedTechnology

RingCentral Data Breach (July 2026)

RingCentral disclosed a social engineering attack in July, ShinyHunters published the data in August, and Have I Been Pwned verified 1.6 million customer records with names, addresses and phone numbers.

Disclosed Updated
Organization
RingCentral
Country
United States, CA
Incident date
July 27, 2026
Disclosed
July 28, 2026
Records affected
1.6 million
Threat actor
ShinyHunters
Status
Confirmed
Data exposed
  • Email addresses
  • Names
  • Phone numbers
  • Physical addresses
Timeline
  1. ShinyHunters lists RingCentral on its leak site, claiming 623 GB of data
  2. RingCentral discloses the incident, describing a sophisticated social engineering campaign
  3. With no payment made, the group publishes a 280 GB archive
  4. Have I Been Pwned loads 1.6 million verified email addresses from the archive

What Happened

RingCentral, the cloud phone and messaging platform used by more than 600,000 businesses, disclosed on July 28, 2026 that it had been the target of what it called a "sophisticated social engineering campaign," according to BleepingComputer's report. The company said it stopped the unauthorized activity on detection, brought in a third-party forensic firm, and had seen no further unauthorized activity since. It also said the incident affected data for a limited portion of customers, that those customers were being contacted directly, and that the core platform was not affected.

RingCentral did not name the attacker. The ShinyHunters extortion group had listed the company on its leak site the day before the disclosure, claiming 623 GB of data, per SecurityWeek. When no payment followed, the group published a 280 GB archive roughly a week later. Have I Been Pwned analyzed it and, on August 13, loaded approximately 1.6 million unique email addresses with names, physical addresses and phone numbers, which is how the record count on this page was established.

The attack type on the fact grid is social engineering because that is the company's own description. RingCentral has not said which employees or systems were targeted. ShinyHunters has spent the past year claiming intrusions at hundreds of companies through their Salesforce and related SaaS environments, typically by talking staff into granting access, but the company has not confirmed that route here.

What was Exposed

Per the Have I Been Pwned entry, the verified data holds email addresses, names, physical addresses and phone numbers. No passwords, call recordings, messages or payment details appear in the data classes. The company's statement that its core platform was not affected is consistent with that: this reads as customer relationship data rather than the service itself.

For the people in it, mostly business users, the risk is impersonation. A scammer now has a work email address, a phone number and the knowledge that the person's company uses RingCentral. That is enough to write a convincing "your RingCentral account needs re-verification" message or to call the switchboard pretending to be support.

What to do if you are Affected

The pattern the follow-on messages will use is described in what phishing looks like, and the general order of operations is in what to do after a data breach. If your company runs on this kind of hosted platform without anyone watching the admin accounts, the managed detection firms on the national list are the people who do that for a living.

What is not Known Yet

Which systems were accessed, how many customers received direct notice, and whether any regulator filing follows. The report will be updated as the record grows.

Sources

  1. Have I Been Pwned: RingCentral
  2. SecurityWeek, 1.6 Million Likely Impacted by RingCentral Data Breach, August 14, 2026
  3. BleepingComputer, RingCentral data breach exposed info of 1.6 million accounts, August 14, 2026
  4. RingCentral security bulletins
On this page
Reviewed by

Daniel Reyes

  • CISSP
  • 12 years in security operations
  • Austin, TX

Daniel Reyes is a CISSP who spent twelve years in security operations, most recently leading a detection and response team for a mid-sized healthcare group in Texas. He reviews every resource and breach report on Cyber Security Firms for technical accuracy before it publishes.

Most of the people he has trained arrived having been told too much: a dozen acronyms, six vendors, and no clear idea which risk was theirs. His approach is to explain what an attack actually does before naming the tool that stops it, on the basis that most breaches start with something a reader could have recognised.

Read the full bio and how we research →