
The ShinyHunters extortion gang breached cloud communications platform RingCentral in July 2026 through a social engineering campaign, then stole 623 GB of company data and leaked 280 GB on their dark web site after RingCentral refused to pay a ransom. The breach notification service Have I Been Pwned has since confirmed that the leaked archive contains records for 1.6 million accounts, including names, email addresses, phone numbers, and physical addresses.
RingCentral is used by over 600,000 businesses for calling, messaging, voicemail, and collaboration services. The company first disclosed the incident on July 28, describing it as resulting from a “sophisticated social engineering campaign,” and said it had not seen new unauthorized activity since taking remediation steps. RingCentral told affected customers it was reaching out to them directly and emphasized that the breach did not impact the core platform or disrupt services. ShinyHunters has claimed breaches at hundreds of Salesforce customers over the past year and was linked to the wave of Snowflake customer breaches in 2024 — following a consistent pattern of targeting cloud-hosted data through credential compromise and social engineering rather than exploiting software vulnerabilities.
How to check if you’re affected
Affected versions include any RingCentral accounts whose data was extracted by ShinyHunters in July 2026 — RingCentral said it is contacting affected customers directly. You can also search for your email address at HaveIBeenPwned.com to see if your account appears in the leaked dataset. If RingCentral has not contacted you, the company says you are not affected.
