A cloud communications company that sells businesses the infrastructure to handle phone calls was itself compromised via a phone call — and the 1.6 million people whose contact profiles were leaked are now prime targets for the exact same attack that hit their provider. The story was first reported by BleepingComputer on August 14, 2026.
The cybercriminal extortion group ShinyHunters added RingCentral to its Tor-hosted dark web leak site on July 27, 2026, claiming to have stolen more than 623 gigabytes of data and setting a July 30 deadline for payment. RingCentral — which provides cloud-based calling, messaging, and voicemail to more than 600,000 businesses — publicly disclosed the intrusion on July 28, describing it as a “sophisticated social engineering campaign.” The company did not pay the extortion demand. On August 3, ShinyHunters published a compressed 280-gigabyte archive of files the group claimed to have stolen, as confirmed by The Register.
On August 13, the breach notification service Have I Been Pwned (HIBP) analyzed that archive and added it to its public breach database, counting approximately 1.6 million unique email addresses, each accompanied by the account holder’s full name, phone number, and physical address. That four-element combination — name, email, phone, address — is precisely what a skilled caller needs to run a convincing impersonation attack. The breach effectively packaged a vishing toolkit and distributed it to anyone who downloaded the archive.
How ShinyHunters Got In: A Phone Call
A ShinyHunters spokesperson told The Register that the group gained entry by voice-phishing a RingCentral employee — calling them on the phone and persuading them to hand over their password.
Voice phishing, or vishing, is the technique that has defined ShinyHunters’ 2026 campaign. The attack pattern, documented by Google Mandiant across multiple tracked clusters (designated UNC6240, UNC6661, and UNC6671), works as follows: attackers call an employee while posing as IT support, directing them to a credential-harvesting website that mimics the company’s real login page in real time. When the employee enters their authentication code, the attackers capture and replay it before the time-based code expires — typically within 30 seconds. Standard one-time password multi-factor authentication does not stop this attack because it relies on the employee cooperating with what sounds like a legitimate IT request. The attacker does not need to break cryptography; they only need to sound credible over a phone call.
Phishing-resistant authentication methods such as FIDO2 passkeys would have blocked the attack structurally. A FIDO2 credential is cryptographically bound to the specific domain where it was registered — a fake harvesting site cannot relay a passkey response because the domain signature does not match, regardless of how convincing the caller sounds. RingCentral has not disclosed what authentication method the compromised account used or whether phishing-resistant alternatives were available.
The irony of the attack vector is not incidental. RingCentral’s core product is business phone infrastructure — the calling and messaging platform that its customers use for IT support callbacks, customer service, and internal communications. The company was breached via the same channel it provides as a service to 600,000 businesses.
RingCentral Told Users They Were Safe. Have I Been Pwned Found 1.6 Million Who May Not Be
In its public disclosure, RingCentral offered affected customers a specific assurance: “If you are not contacted by RingCentral, you are not affected. This incident did not impact the core RingCentral platform, and our services continue to operate without disruption.” — per the RingCentral trust center security bulletin.
That reassurance is now materially complicated by HIBP’s public record. Have I Been Pwned independently analyzed the leaked archive and identified approximately 1.6 million unique accounts — a figure RingCentral has neither confirmed nor denied. As of August 15, 2026, the company has not disclosed how many individuals it has directly notified, nor confirmed how the attackers’ access translated into 1.6 million exposed records from what it described as “a limited portion” of its customers.
The gap matters legally as well as practically. US state data breach notification laws across all 50 states impose notification obligations when personal information is “acquired” or “accessed” by an unauthorized party — the statutory standard is not whether the company determined that specific individuals were harmed, but whether their data was taken. A company’s internal conclusion that affected customers constitute a “limited portion” of its user base does not substitute for the independent accountability provided by HIBP’s public verification. Whether RingCentral’s notification scope aligns with its legal obligations under applicable state statutes is a question the company has not publicly addressed.
Analysis by SQ Magazine noted that anyone in HIBP’s RingCentral breach entry has a pretexting problem before an account problem. A full name, a working phone number, and a street address are the raw materials for a social engineering call — and those calls will now reference details that a victim cannot tell apart from a legitimate RingCentral support inquiry.
The Recursive Threat: Victims Now Face the Same Attack That Hit RingCentral
The data exposed in the RingCentral breach creates a specific secondary exposure that distinguishes it from most enterprise database leaks. Most breach databases contain email addresses and hashed passwords — useful for credential-stuffing attacks but limited in social engineering utility. The RingCentral dataset includes the physical address and phone number of every account holder, meaning attackers have a complete contact profile for 1.6 million people who work at or manage communications infrastructure for their organizations.
An attacker with this dataset can call a RingCentral account holder, address them by name, reference their known employer, and claim to be from RingCentral support following up on the recent security incident. That caller will sound more credible than a cold-call vishing attempt because they can pretext details that the victim will recognize as accurate. The leaked data is, in effect, a targeting list for the next campaign — and that next campaign can use exactly the vishing technique that produced the list.
The pattern has played out before. After ShinyHunters breached Aura — a company that sells identity theft protection services — in March 2026 via an employee vishing call, security researchers noted that Aura’s breach was particularly dangerous because the victim population had specifically sought protection against the type of attack now enabled by their stolen data. The Aura incident is documented on Wikipedia. RingCentral’s situation carries a structurally similar irony: its customers are businesses whose communications the company was trusted to secure, and the breach has handed attackers the tools to exploit the trust those businesses placed in RingCentral’s brand.
Who Is ShinyHunters?
ShinyHunters is a financially motivated cybercriminal extortion group that has operated since 2019 and is now documented as one of the most prolific data theft enterprises in history. The group is affiliated with The Com, a loose international network of cybercriminals that overlaps with Scattered Spider and Lapsus$ membership.
The group does not deploy ransomware encryption. Its model is data exfiltration and extortion: steal records, post the victim to a Tor-hosted leak site with a payment deadline, and publish if the target refuses to engage. When ShinyHunters follows through on a deadline — as it did with RingCentral — the group’s standard statement reads: “The company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don’t care.”
By early 2026, ShinyHunters claimed to have breached between 300 and 400 organizations in a single campaign wave targeting Salesforce Experience Cloud misconfigurations, asserting the theft of more than 1.5 billion records. Other confirmed or claimed victims in 2026 alone include Abbott’s cancer diagnostics business (10.9 million email addresses dumped; breached via a vishing call on employees in mid-June, per The Register’s report on Abbott’s breach), Odido (6.5 million identity records, Netherlands), ADT (5.5 million people), and Carnival Cruise (6 million people).
Multiple law enforcement actions have targeted the group without meaningfully disrupting its operations. French national Sébastien Raoult was sentenced in January 2024 to three years in prison and $5 million in restitution after pleading guilty to conspiracy charges. Four additional suspected members were arrested in France in June 2025. The group continued operating through and after both actions, reflecting its deliberately decentralized structure across overlapping, loosely affiliated cells.
Refusing to Pay Is the Right Call — Though It Costs You
The FBI’s Internet Crime Complaint Center issued a formal advisory in May 2026 warning organizations about ShinyHunters’ tactics — including harassment escalation strategies such as threatening calls and swatting directed at victim organizations — and strongly advised against paying extortion demands on the grounds that payment funds future attacks, rarely guarantees data deletion, and frequently invites repeat targeting.
Allison Nixon, chief research officer at cybersecurity firm Unit 221B, has urged targeted organizations to resist the group’s pressure. “They rely on the intensity of their emotional manipulation to force you to make a snap decision, within 72 hours, to pay the ransom,” Nixon has said publicly. “They don’t have a convincing argument about why you should pay in the first place. Their only answer to you is that they will hurt you. But that’s not a rational answer.”
What RingCentral Users Should Do Now
The data exposed in the RingCentral breach enables targeted attacks that passive precautions cannot block. A name, phone number, email address, and physical address in the wrong hands is not just a phishing dataset — it is a calling script. Anyone who has or had a RingCentral account should take the following steps.
Check HIBP first. Visit haveibeenpwned.com and search your email address to confirm whether your account appears in the RingCentral dataset. RingCentral’s assurance that unreached customers are unaffected cannot substitute for an independent check, given that HIBP identified 1.6 million records the company has not publicly acknowledged.
Treat unexpected inbound calls as hostile until verified. The leaked data enables highly specific pretexting: callers may use your name, your employer’s name, and your phone number correctly while posing as RingCentral support, IT staff, or a security team following up on the breach. Hang up on any unexpected call referencing your RingCentral account and verify through a separately initiated call to a number found independently — not one provided by the incoming caller.
Watch for targeted phishing email. Attackers with your email address and employer context can craft messages that reference your specific job role, your known contact details, or the breach itself as a pretext. Heightened skepticism toward any email requesting credential updates, account verification, or link clicks is warranted for the foreseeable future.
Update passwords on any account that shared credentials with your RingCentral login. If you reused the same email and password combination on other platforms, change those credentials immediately and enable the strongest available authentication method on each.
Frequently Asked Questions
How did ShinyHunters get into RingCentral’s systems?
A ShinyHunters spokesperson told The Register that the group breached RingCentral by voice-phishing an employee — calling them on the phone and convincing them to hand over their account password. RingCentral described the incident only as a “sophisticated social engineering campaign” and has not publicly confirmed the attack method or identified the systems that were accessed. The vishing technique ShinyHunters uses against enterprise targets typically involves calling employees while posing as IT support, directing them to a fake login page that captures their credentials and authentication codes in real time — allowing attackers to log in as the employee before the one-time code expires.
How do I know if my data was leaked?
Check Have I Been Pwned (haveibeenpwned.com) and search your email address. HIBP independently analyzed the leaked archive and confirmed approximately 1.6 million accounts are in the dataset, each with the account holder’s name, phone number, and physical address. RingCentral has said it is directly contacting affected customers, but HIBP’s independent verification covers accounts the company has not confirmed publicly — so checking HIBP yourself is the only way to know for certain.
Why are the 1.6 million people in this breach at particular risk of further vishing attacks?
Because the specific data types exposed — name, phone number, email, physical address — are exactly what an attacker needs to make a vishing call convincing. Unlike a typical breach that yields only email addresses and hashed passwords, this dataset gives attackers a complete contact profile for each victim. A caller using this data can address you by name, reference your employer, and claim to be from RingCentral support following up on the security incident — all details that are true and verifiable, making it extremely difficult to distinguish a fraudulent call from a legitimate one. Treat any unexpected inbound call referencing RingCentral with hostility until you have independently verified the caller’s identity through a separately initiated contact.
Does RingCentral’s “if not contacted, you’re unaffected” statement protect me legally?
It does not establish any legal protection for affected individuals. US state data breach notification laws generally require companies to notify individuals whose personal information was acquired by an unauthorized party — the legal standard is based on the access event, not on the company’s assessment of individual harm. HIBP’s independent verification of 1.6 million accounts raises questions about whether RingCentral’s notification scope covers every individual entitled to notice under applicable statutes. Those questions are unresolved as of publication. If you believe your data was exposed and you have not received a notification, your state attorney general’s office is the relevant contact for reporting potential notification violations.
Click Here For The Original Source.
