TechNewsReel
Live

RingCentral Confirms Data Breach After ShinyHunters Extortion Attempt

The cloud communications provider acknowledged a security incident after the ShinyHunters group claimed to have stolen 623GB of data.

TechNewsReel Newsroom · August 14, 2026

RingCentral has confirmed a security incident affecting a portion of its customer base following extortion attempts by the cybercrime group ShinyHunters. The breach highlights the growing risk to cloud communications infrastructure as threat actors pivot toward identity-focused attacks.

The incident first came to light on July 27, 2026, when ShinyHunters listed RingCentral on its leak portal. The group claimed to have exfiltrated 623GB of uncompressed data, which totals over 280GB when compressed. On August 3, 2026, the attackers updated their claims, alleging that RingCentral had ignored their attempts to negotiate. While the group initially operated in the shadows, RingCentral subsequently issued a disclosure notice via its trust center, stating that the incident affected a limited portion of its customers.

A Shift in Attacker Tactics

This breach is part of a broader 2026 campaign by ShinyHunters that targeted multiple high-profile organizations, including EY and Brink's Home. The group has notably evolved its methodology over the last year, moving away from traditional ransomware encryption. Instead, ShinyHunters now focuses on credential harvesting, identity-focused social engineering, and the exploitation of single sign-on (SSO) platforms to penetrate SaaS providers and enterprise networks.

Industry Implications

As a primary provider of cloud-based communications, RingCentral sits at the center of the digital workflows for thousands of enterprise clients. A breach of this nature is particularly critical because it potentially exposes sensitive business communications and administrative credentials. The shift toward SSO abuse demonstrated in this campaign suggests that traditional perimeter defenses are becoming less effective against attackers who can compromise a single identity provider to gain wide-scale access to cloud environments.

Current Status

While RingCentral has acknowledged the event, the full scope of the exfiltrated data remains a point of concern. The company's trust center has confirmed the impact on customers, but the specific nature of the stolen files—beyond the volume claimed by ShinyHunters—has not been fully detailed. Security researchers continue to monitor the group's leak portal to determine if the 623GB of data will be published publicly or if the extortion attempt will remain unresolved.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.