Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Data Breaches » ShinyHunters Claims RingCentral Breach Exposed Data of 1.6 Million Customers

ShinyHunters Claims RingCentral Breach Exposed Data of 1.6 Million Customers

By:
Last updated:August 17, 2026
Human Written
  • ShinyHunters reportedly got into RingCentral’s systems by tricking an employee into giving up their password over the phone.

  • The attack appears to have exposed data from 1.6 million customers, emails, names, phone numbers, home addresses, etc.

  • RingCentral says the breach affected some customers, while their main services remain unaffected.

ShinyHunters Claims RingCentral Breach Exposed Data of 1.6 Million Customers

RingCentral suffered a data breach, allegedly exposing customer information. The notorious cyber extortion group ShinyHunters has taken credit for the attack. They claimed they obtained access through voice phishing.

Notably, ShinyHunters demanded money, but RingCentral refused to comply, which led them to publish the stolen data online.

RingCentral has confirmed that there was an attack. But so far, they haven’t come out and said ShinyHunters were behind it. They’ve also not clarified how much data leaked.

RingCentral Confirms a Social Engineering Attack

RingCentral disclosed the incident in a security advisory dated July 28. The company described the attack as a “sophisticated social engineering campaign” and says their team managed to shut it down once they found out. They also brought in an outside forensic firm to dig into exactly what happened. 

Since that investigation, there hasn’t been any more unauthorized activity. Only a small group of customers had their data involved, and RingCentral says they’ll contact those people directly.

RingCentral stressed that the attack didn’t affect its main platform.  Its services continued to operate without disruption. That distinction matters. A breach of customer data does not mean attackers took control of RingCentral’s phone services.

ShinyHunters Claims a Phone Call Opened the Door

The most striking detail came from ShinyHunters itself. The group told The Register that it gained entry by voice phishing an employee. In simple terms, someone called a worker and convinced them to reveal information needed to access company systems.

There was reportedly no software flaw involved. ShinyHunters listed RingCentral on its leak site on July 27. The group claimed it had stolen more than 623GB of data and gave RingCentral until July 30 to pay.

When the deadline passed, the attackers said RingCentral had not reached an agreement. So they released the stolen information. The timing closely matches RingCentral’s disclosure. ShinyHunters listed the company on July 27, while RingCentral issued its advisory the next day.

However, there’s a need to approach the claims with caution. While RingCentral has admitted the attack and social engineering attack, the company has never made an official statement confirming ShinyHunters conducted the attack.

The Leaked Data Creates a Second Threat

Have I Been Pawned logged about 1.6 million compromised email addresses linked to this attack. But the reported information goes beyond email addresses. It also exposed names, home addresses, and phone numbers.

That combination can be valuable to criminals. People can change passwords. But home addresses and phone numbers are much more difficult to change. This information can help attackers impersonate a bank, the user’s employer, phone provider or any other person who may have communicated with the victim.

The risk is even greater because ShinyHunters already uses voice phishing. Google Threat Intelligence reported in January that ShinyHunters-linked activity relied heavily on phone calls and fake login pages.

Attackers used stolen credentials and authentication codes to enter cloud services. The leaked RingCentral data could therefore help criminals make future calls more convincing.

This is not an Isolated ShinyHunters Tactic

ShinyHunters has repeatedly used social engineering to target companies. Google researchers have tracked campaigns linked to ShinyHunters that combine voice phishing with stolen credentials and cloud access. The attackers often target employees rather than trying to break through a technical security flaw.

In February 2026, the group hit Dutch telecom provider Odido using a nearly identical playbook, voice-phishing a helpdesk employee into logging into a fake website. The breach exposed data from 6.2 million customer accounts, and when Odido refused to pay the €1 million ransom demand, ShinyHunters leaked the full dataset online, calling it “the largest data leak in the Netherlands.”

This group knows how to switch tactics when it matters. Google and Mandiant tied ShinyHunters to over a hundred attacks in June. Each and every one of them had focused on an Oracle PeopleSoft flaw with the CVE-2026-35273 designation, a highly severe issue rated at 9.8 level. The vulnerability could allow remote code execution without logging in.

Google said that of the 100 organizations they notified, 68% were in higher education. The campaign affected roughly 300 PeopleSoft instances. That campaign required technical skills. The RingCentral attack allegedly did not.

That contrast shows why social engineering remains so dangerous. A company can patch software and still struggle to stop a convincing phone call.

Other Victims Show the Same Pattern

The RingCentral incident also comes as ShinyHunters targets several other major organizations. The group listed Ernst & Young on its leak site on July 27. It claimed stolen credentials from a supply-chain attack gave it access to EY systems.

EY had already disclosed a breach involving a third-party IT support system. The company said the attackers may have stolen documents containing client tax information. However, EY has not publicly confirmed that ShinyHunters caused the breach. The group’s claims about additional access also remain unverified.

ShinyHunters leaked data connected to Moody Bible Institute earlier this year. Have I Been Pwned flagged over 2.3 million unique email addresses from that breach, plus names, addresses, and phone numbers.

This incident is part of a bigger issue.  Attackers do not always need to defeat a firewall. Sometimes they only need to persuade the right person.

What RingCentral Customers Should Watch for

People whose information was exposed should expect more convincing scams. A caller may already know a person’s name, phone number and address. That can make a fake support call sound genuine. Customers should be especially careful with unexpected requests for passwords, verification codes or account changes.

Just because someone on the phone knows your info doesn’t mean you should trust them. Hang up and call the company yourself using a number you know is legit or go straight to their website.

RingCentral says they’ll reach out directly to the victims. If you haven’t heard from them, their advisory says you’re in the clear. The bigger lesson is harder to solve. Security tools can block malware and patch software flaws. They cannot stop an employee from trusting the wrong caller.

For RingCentral, a company built around business communications, that makes the alleged attack especially striking. The phone was not just the product. It was reportedly the way attackers got in.

Share this article

About the Author

Joahn G

Joahn G

Cyber Threat Journalist

Joahn is a cyber threat journalist dedicated to tracking the evolving landscape of digital risks. His reporting focuses on ransomware gangs, data breach incidents, and state-sponsored cyber operations. By analyzing threat actor motives and tactics, he provides timely intelligence that helps readers understand and anticipate the security challenges of tomorrow.

View all posts by Joahn G >
Comments (0)

No comments.