Some 1.6 million unique email addresses tied to RingCentral have been posted online alongside names, physical addresses and phone numbers, according to Have I Been Pwned.
RingCentral's July 28 disclosure and immediate response
RingCentral notified customers on July 28 that “it was the target of a sophisticated social engineering campaign” that affected a “limited portion of RingCentral customers.” The company said it “promptly responded to the intrusion upon detecting it, took steps to stop the unauthorized activity,” and “immediately launched an investigation into the security incident with help from a leading third-party forensic firm.” RingCentral also said: “We have not seen any new unauthorized activity since taking these remediation efforts.”
ShinyHunters' extortion claim and timeline
Although RingCentral did not name an attacker in its notice, the data-theft and extortion gang ShinyHunters publicly claimed responsibility on its own data leak site and set a July 30 deadline for payment. ShinyHunters said it had taken more than 623 GB of data and threatened to publish the haul if RingCentral did not pay. After RingCentral apparently declined to accede to the demand, ShinyHunters posted customers’ details online. On August 3 the group wrote: “The company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don’t care.”

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleWhat was posted: volumes and types of data
Have I Been Pwned reported that roughly 1.6 million unique email addresses tied to RingCentral were leaked, alongside names, physical addresses and phone numbers. Screenshots of the ShinyHunters post circulated on social media, and The Register viewed the gang’s post on its leak site. ShinyHunters has not publicly detailed the precise mechanics of how it gained access to RingCentral systems; the group “hasn’t said how it gained access to RingCentral,” according to reporting.
ShinyHunters' recent activity and a pattern of large dumps
Security sleuth Dominic Alvieri is quoted saying ShinyHunters is his “top threat group and probably is for most analysts.” The group has claimed responsibility for hundreds of breaches since the start of the year, including incidents affecting education-technology firms and healthcare organizations. In a recent separate incident involving Abbott’s cancer diagnostics business, ShinyHunters’ dump reportedly contained 10.9 million unique email addresses and a range of personal and health information. In that disclosure the group claimed more than 30 million rows of customer information, including more than one million Social Security numbers, 7.5 million dates of birth, 22 million-plus rows of client notes containing confidential doctor-patient conversations and health information, and more than 20 million medical-order records containing patient IDs, prescription types, order dates and refill information.
How technologists, affected enterprises, and end users are positioned by these facts
- Technologists and security teams: RingCentral’s description of a “sophisticated social engineering campaign” and its use of a leading third-party forensic firm make clear that incident response and forensic remediation are central activities in the wake of the dump. Monitoring for any additional unauthorized activity will be a primary technical focus, consistent with the company’s statement that it has not seen new unauthorized activity since remediation.
- Affected enterprises and procurement leaders: The breach notification describes a “limited portion of RingCentral customers” as impacted, but the public posting of customer details by an extortion group underscores the operational and contractual exposure enterprises must now reconcile with their communications provider.
- End users and customers: Have I Been Pwned’s reporting that 1.6 million unique email addresses tied to RingCentral were leaked — together with names, addresses and phone numbers — means personal contact details were among the material posted online; customers will need to check whether their information appears in the disclosed data.
The immediate, verifiable thread running through this episode is clear: RingCentral detected and publicly disclosed a social-engineering-driven intrusion, engaged external forensics, and says it has halted further unauthorized activity — yet an extortion group has posted a large dataset and claimed hundreds of breaches elsewhere. The principal unanswered fact recorded in the public record is also simple and consequential: ShinyHunters “hasn’t said how it gained access to RingCentral.” That detail will determine whether the incident is an isolated compromise of certain accounts or part of a broader pattern the company and its customers should expect to see repeated.
Source: The Register — 1.6M RingCentral accounts' data dumped after ShinyHunters extortion attack




