
Cloud communications provider RingCentral hit by ShinyHunters extortion, 1.6 million account records exposed
Cybercrime group ShinyHunters leaked data from 1.6 million RingCentral accounts after the company refused to pay a ransom, Have I Been Pwned confirms.
Cloud-based business communications platform RingCentral has become the latest target of the ShinyHunters extortion group, resulting in the exposure of personal information tied to 1.6 million accounts. The breach, which the company disclosed on July 28, followed what RingCentral described as a sophisticated social engineering campaign, a type of attack where criminals manipulate people into giving up access rather than breaking through technical defenses. Have I Been Pwned, a widely used service that lets people check whether their data has appeared in known breaches, confirmed the number of affected records on Thursday after analyzing files leaked by the attackers.
RingCentral said the incident affected only a limited portion of its customer base and that it is contacting affected customers directly. The company also stressed that the core RingCentral platform was not impacted and that services continued to operate without disruption. However, despite the company's assurances, the ShinyHunters group had claimed responsibility a day earlier, on July 27, saying it had stolen 623 gigabytes of data. When RingCentral refused to pay a ransom to have the stolen information destroyed, the cybercrime group published a compressed archive containing 280 gigabytes of files on its dark web leak site.
The leaked records include names, email addresses, phone numbers, and physical addresses. Such a combination of personal details is valuable to criminals for targeted phishing, identity theft, and account takeover attempts. For website owners and businesses that use RingCentral for calling, messaging, and voicemail, this means employees and customers could receive more convincing fraudulent messages that reference real names, phone numbers, or addresses. Attackers often use leaked data from one service to craft emails or text messages that appear legitimate, increasing the chance that someone clicks a malicious link or shares a password.
ShinyHunters is a well-known extortion gang that has claimed breaches at hundreds of organizations over the past year, including more than a dozen Snowflake customers and various third-party integration providers. The group has said it stole over 1.5 billion records in campaigns targeting Salesloft Drift and Salesforce Aura, and more recently claimed responsibility for a new series of breaches at over 100 organizations by exploiting an Oracle PeopleSoft zero-day flaw. A zero-day flaw is a software vulnerability that the vendor does not yet know about or has not had time to patch, giving attackers a window to break in before a fix is available. RingCentral has not attributed the breach to a specific threat actor or shared exactly how the attackers gained access, but the pattern of ShinyHunters' previous claims and the timing of the leak make the group's involvement highly credible.
For any organization that manages customer data, this incident is a reminder that even well-known cloud platforms can be compromised through human error rather than technical weakness. Social engineering attacks often start with a single employee being tricked into revealing credentials or approving a fraudulent request. Once attackers have valid login details, many security tools are far less effective. Research referenced by the article notes that once attackers have valid credentials, only 37 percent of their actions are blocked, underscoring the need for strong identity protection and monitoring of unusual login activity.
Because stolen contact information can be used to impersonate trusted brands and trick people into giving up passwords or financial details, businesses should review their incident response plans and remind staff to treat unexpected requests for credentials or urgent payment changes with suspicion. For readers who manage websites or rely on cloud services, AEU Hosting's managed WordPress hosting includes security-first protections that reduce the risk of credential-based attacks on your own web infrastructure, and regularly reinforcing basic security habits among your team helps limit the damage when a third-party service you use is breached.
How to Protect Yourself
- Check if your email address appears in the RingCentral breach using the free Have I Been Pwned website, and take any warning seriously.
- Change the password on your RingCentral account and any other accounts that used the same password, choosing a long unique password for each one.
- Turn on two-factor authentication (a second step to log in, like a code from an app or text message) for RingCentral and any important accounts that offer it.
- Be extra careful with emails or text messages that mention RingCentral, especially if they ask you to click a link or provide personal information, even if they include your real name or phone number.
- If you run a business, remind your team that no legitimate IT support will ask for passwords over email or phone, and report any suspicious request immediately.