ShinyHunters has dumped data tied to roughly 1.6 million RingCentral accounts after the collaboration platform refused to pay an extortion demand, according to Have I Been Pwned.
The leaked records include unique email addresses, names, physical addresses, and phone numbers. RingCentral disclosed the intrusion on July 28, describing it as the work of a sophisticated social engineering campaign that touched a limited portion of its customer base.
The company said it stopped the unauthorized activity, launched an investigation with a third-party forensics firm, and has seen no new intrusions since taking remediation steps.
A ShinyHunters spokesperson told The Register the crew broke in by voice-phishing an employee and convincing them to hand over a password. The group claimed it stole more than 623 GB of data and set a July 30 deadline for payment. When RingCentral did not pay, the criminals posted customer details on their leak site on August 3.
ShinyHunters is one of the most active data theft gangs of the year, with security researcher Dominic Alvieri calling it the top threat group for most analysts. Its recent victims include education technology firms, universities, healthcare organizations, and Abbott’s cancer diagnostics business, whose leaked haul contained 10.9 million email addresses.
For RingCentral customers, the practical risk is credential stuffing and targeted phishing built on the exposed email addresses and phone numbers. Anyone with an account should change passwords, enable multi-factor authentication, and treat unexpected calls or messages referencing RingCentral with suspicion. The breach also underscores how a single vishing call can bypass otherwise solid perimeter defenses.
RingCentral has not named the attacker publicly, but the timing and claimed volume line up with ShinyHunters’ own statements. Organizations using the platform should monitor for account takeover attempts and review logs for unusual authentication activity.
