01Summary
ShinyHunters got into RingCentral in July 2026 through social engineering, claimed the attack on 27 July and demanded a ransom. RingCentral disclosed the breach on 28 July. It refused to pay, and the group leaked a 280 GB archive out of 623 GB stolen. Have I Been Pwned confirmed 1.6 million accounts on 13 August. Each record contains a name, email, physical address and phone number. The core platform was unaffected.
02Victims and impact
Countries affected
- United States
03Data exposed
Data types
- Names
- Email addresses
- Physical addresses
- Phone numbers
04Timeline
- 2026-07-27ShinyHunters claims the attack and demands a ransom.
- 2026-07-28RingCentral discloses the breach.
- 2026-08-13Have I Been Pwned confirms 1.6 million accounts.
05Disclosure and media
Publishing organisations
- BleepingComputer
- SecurityWeek
- The Register
06Sources
References
- [1]BleepingComputer: https://www.bleepingcomputer.com/news/security/ringcentral-data-breach-exposed-info-of-16-million-accounts/
- [2]The Register: https://www.theregister.com/cyber-crime/2026/08/14/16m-ringcentral-accounts-data-dumped-after-shinyhunters-extortion-attack/5288003









