ShinyHunters Leaks Data of 1.6 Million RingCentral Users After Failed Extortion
The cloud communications giant saw a massive data dump after refusing to pay a 'pay or leak' demand from a notorious threat actor group.
Cloud communications provider RingCentral has suffered a significant data breach affecting approximately 1.6 million user accounts. The leak follows a failed extortion attempt by the threat actor group known as ShinyHunters, who dumped the data after their demands were not met.
The breach occurred on July 27, 2026, when ShinyHunters targeted the platform in a "pay or leak" campaign. The group claimed to have stolen 623GB of internal data; however, when the extortion attempt failed, the attackers leaked a 280GB archive containing the records. The exposed information includes names, email addresses, phone numbers, and physical addresses. RingCentral stated in a disclosure notice that the incident affected "a limited portion of RingCentral customers."
The Extortion Pattern
RingCentral provides essential cloud-based business communications, including VoIP, messaging, and video services. The group responsible for the attack, ShinyHunters, is a well-known extortion entity that frequently targets high-profile corporations. Their typical modus operandi involves gaining access to internal databases and attempting to coerce companies into paying ransoms to prevent the public release of sensitive information. In this instance, the transition from a private extortion attempt to a public data dump confirms the group's willingness to release data when their financial demands are ignored.
Risks to Corporate Security
The exposure of this specific dataset creates a heightened security risk for the affected business accounts. Because the leak includes both phone numbers and physical addresses alongside professional email addresses, it provides a blueprint for highly targeted social engineering. Security experts warn that this data significantly increases the likelihood of sophisticated phishing and "smishing" (SMS phishing) attacks. By leveraging concrete personal details, attackers can craft more convincing lures to deceive corporate employees, potentially gaining further access to internal company networks or sensitive corporate data.
Verification and Next Steps
The breach was verified and added to the breach-tracking service Have I Been Pwned in August 2026, allowing affected users to confirm if their data was part of the leak. While the volume of leaked data is substantial, the full extent of the 623GB claimed by ShinyHunters remains a point of interest, as only a 280GB archive was officially dumped. Organizations using RingCentral are advised to alert their employees to be vigilant against unsolicited communications and to implement stricter multi-factor authentication protocols to mitigate the risk of credential-based attacks.