1.6 Million Users’ Data Compromised in RingCentral Breach Linked to ShinyHunters Group

Published:

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

The personal information of 1.6 million individuals appears to have been stolen from the widely used business communications platform RingCentral by a notorious extortion group. The incident occurred in July and was the result of a “sophisticated social engineering campaign,” according to a notice on RingCentral’s website.

Upon detection, the company stated, “we promptly took steps to stop the unauthorized activity and immediately began an investigation with assistance from a leading third-party forensic firm. We have not seen any new unauthorized activity since taking these remediation efforts.”

RingCentral reported that only a limited portion of its customers was affected by the attack, and those individuals were notified directly. The company emphasized, “If you are not contacted by RingCentral, you are not affected. This incident did not impact the core RingCentral platform, and our services continue to operate without disruption.”

While RingCentral did not name the attackers, the ShinyHunters extortion group added the company to its Tor-based leak site in late July, claiming it stole over 623 gigabytes of data. Roughly a week later, as RingCentral did not succumb to the extortionists’ demands, ShinyHunters published a 280GB archive containing the data allegedly stolen from the company.

On Thursday, data breach reporting site HaveIBeenPwned added the leaked information to its database, stating that it includes approximately 1.6 million unique email addresses, accompanied by names, addresses, and phone numbers. RingCentral has yet to confirm the attackers’ claims and the number of potentially impacted individuals. SecurityWeek has emailed RingCentral for a statement on the matter and will update this article if the company responds.

RingCentral is a cloud-based provider of unified communications and contact center solutions, delivering business phone, team messaging, video meetings, and AI-assisted tools for employee collaboration and customer interactions.

Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Air Force retires EC-130H Compass Call, replacing it with EA-37B

WASHINGTON — The Air Force has formally retired the EC-130H Compass Call, concluding over 40 years of operations for this electronic attack aircraft. The...

AI-Driven Research Uncovers HEIF Heist Vulnerability in Popular Software Decoders

Researchers have identified a significant vulnerability, dubbed the "HEIF Heist," in popular software decoding tools that could expose major internet platforms and enterprise services...

North Korean Threat Actor Jade Sleet Compromises Indian IT Provider Using FLATROOF and ROOFDECK Backdoors

The North Korean threat actor known as Jade Sleet has been linked to the compromise of a smaller Indian IT services organization, underscoring the...

Seclore Enhances Data-Centric Security Solutions Across Middle East, Turkey, and Africa

Seclore Expands Data-Centric Security Solutions Across META Seclore has unveiled significant advancements in its data-centric security solutions during GISEC Global 2026, focusing on the Middle...