Skip to main content
Emerging ThreatsData Breaches

ShinyHunters Breach Exposes 1.6 Million RingCentral Accounts

Employees work at desks in a modern, brightly-lit office setting with laptops and phones.

"We have not seen any new unauthorized activity since taking these remediation efforts. To date, this incident has affected data for a limited portion of RingCentral customers, and we are communicating with affected customers directly," RingCentral said in its disclosure.

RingCentral's public statement and scope

RingCentral, the cloud-based collaboration and communications platform used by more than 600,000 businesses, disclosed late in July that its systems were compromised following what the company described as a "sophisticated social engineering campaign." The company said the incident affected a limited portion of customers and that its core platform and services continued to operate without disruption. RingCentral also told customers: "If you are not contacted by RingCentral, you are not affected."

ShinyHunters' claim and the leaked archive

Although RingCentral did not attribute the breach to a named group, the extortion gang ShinyHunters claimed responsibility on July 27, saying it had stolen 623GB of data and demanding payment to prevent publication. After RingCentral reportedly refused to pay, ShinyHunters published a compressed archive on its dark-web leak site containing roughly 280GB of files.

Have I Been Pwned confirmation: 1.6 million accounts exposed

Independent analysis by the data-breach notification service Have I Been Pwned linked the leaked material to RingCentral and reported that the published data contained records for 1.6 million accounts. According to Have I Been Pwned, the exposed fields included names, email addresses, phone numbers, and physical addresses. The service's confirmation followed analysis of the files posted by ShinyHunters.

ShinyHunters' recent activity and related breaches

ShinyHunters is not new to high-profile extortion claims. In the year prior to the RingCentral incident the group said it had breached hundreds of Salesforce customers, claiming more than 1.5 billion records in Salesloft, Drift and Salesforce Aura campaigns. The group was also linked to breaches at more than a dozen Snowflake customers and recently claimed responsibility for a series of breaches at over 100 organizations tied to attacks that exploited an Oracle PeopleSoft zero-day flaw. The public claims underscore a pattern in which the group mixes extortion demands with publication of stolen data when ransoms are not paid.

What this means for RingCentral customers, security teams, and adversaries

  • RingCentral customers — The company says it will contact affected customers directly; if a customer has not been contacted by RingCentral, the company has stated that they are not affected. Nonetheless, Have I Been Pwned's finding that names, emails, phone numbers and physical addresses appear in the leaked set means those customers identified in the archive may face phishing, smishing, or impersonation attempts tied to the exposed contact information.
  • Security teams and procurement leaders — RingCentral attributed the incident to a "sophisticated social engineering campaign" but has not shared the exact path the attackers used to gain access. The Blue Report 2026 language included in the public record for this incident notes a familiar technical reality: "Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply." For defenders, that underscores a focus on post-access detection and rapid response in addition to perimeter controls.
  • Adversaries and extortion actors — The sequence of claim, demand, and partial publication shows the operational model ShinyHunters is using: claim a large haul (623GB, by its account), press for payment, and then release portions of the data (280GB in the posted archive) when demands are not met. The group’s prior public claims across Salesforce, Snowflake, and Oracle PeopleSoft customers indicate a campaign strategy that targets integrated cloud services and third-party tooling.

RingCentral has not publicly detailed how the attackers initially gained access to its systems, and the company did not immediately respond to external requests for confirmation about ShinyHunters' claims. Have I Been Pwned's analysis ties the leaked archive to 1.6 million account records and identifies the types of personal data exposed, while ShinyHunters' public assertions place the incident in a broader pattern of extortion-driven publication. The next public steps — more detailed forensic findings from RingCentral and the scope of its direct notifications to affected customers — will determine whether any additional exposed fields or downstream risks emerge.

Original BleepingComputer story