Update: GoSafe Review Identifies Emails, Attachments and Customer Tenant Data
GoSafe has reviewed material made available in connection with the RingCentral breach. The files examined indicate that the incident involves significantly more than basic customer account information.
The exposed material appears to include inbound and outbound emails, including complete message bodies and email attachments. Some of the correspondence reviewed contains confidential and highly sensitive information, including health and medical-related details shared within email conversations.
This is particularly concerning because the sensitivity of an email breach cannot be measured solely by the number of messages exposed. Individual emails and attachments may contain personal information, contractual documents, financial details, customer enquiries, identification documents, internal discussions and other information belonging to RingCentral customers or the people they communicate with.
Phone and Contact-Centre Database Exports
The material also contains a substantial collection of database exports associated with phone-system tenants and contact-centre operations.
The files reviewed include information relating to:
- Customer and tenant accounts
- Agents, agent groups and agent login activity
- Leads and lead lists
- Products, licences, bundles and consumption
- Bills and billing categories
- Queues, campaigns and disposition configurations
- Inbound interactions and communication segments
- Call-handling, queue and waiting-time analytics
- DNIS, ANI and geographic information
- Custom fields and reporting categories
Examples of the filenames identified include Account.csv, Agent.csv, Lead.csv, License.csv, Bill.csv, Queue_Config.csv, Agent_Login.csv, Consumption_Mart.csv, Geo_Location_ANI.csv, Geo_Location_DNIS.csv and numerous interaction and reporting datasets.
The presence of these exports suggests that the exposed information may provide detailed insight into the operations of affected customer environments, including their agents, licences, products, telephone routing, customer interactions and reporting structures.
Internal Shared Files
The breach material also appears to contain files taken from an internal staff shared-drive or document-storage environment. These files may include internal operational documents and other information not ordinarily intended for public access.
The full scope and sensitivity of this portion of the material are still being assessed.
Why the Email Exposure Is Particularly Serious
The exposed email content presents one of the most significant risks identified during the review.
Access to genuine email conversations, attachments, names, signatures and business relationships could allow criminals to create highly convincing phishing, impersonation and payment-redirection attacks. Existing conversations could potentially be reused to approach employees, customers, suppliers or other third parties while appearing to have legitimate context.
Where emails contain medical or other sensitive personal information, publication or misuse could also cause serious privacy and confidentiality harm to the individuals concerned.
RingCentral’s Response
RingCentral has confirmed that it was targeted through what the company describes as a sophisticated social-engineering campaign. The company says it stopped the unauthorised activity, engaged a third-party forensic firm and is contacting affected customers directly.
RingCentral maintains that the incident affected a limited portion of customers and did not affect its core platform or disrupt its services.
The material reviewed by GoSafe provides further evidence concerning the types of information involved. However, its presence does not necessarily mean that every RingCentral customer was affected or that every listed dataset contains information from all customer environments.
Potential Risks
Affected organisations and individuals may face an increased risk of:
- Targeted phishing and social-engineering attacks
- Business email compromise and payment fraud
- Customer or employee impersonation
- Exposure of confidential email conversations and attachments
- Misuse of customer, agent, lead and account information
- Disclosure of medical or other sensitive personal information
- Attacks using knowledge of telephone numbers, queues, agents or internal operations
- Credential-reset and account-takeover attempts
- Reputational, contractual and regulatory consequences
Organisations contacted by RingCentral should carefully review the information provided to them, identify potentially affected users and consider warning employees and customers about targeted communications that reference genuine conversations or business relationships.
GoSafe will continue reviewing the available information and monitoring for further developments.
Update: 29/07/2026
RingCentral has been named in an extortion claim published by the ShinyHunters cybercriminal group.
The listing first appeared on 27 July 2026, with ShinyHunters giving RingCentral until 30 July 2026 to respond before allegedly publishing the stolen information.
The group has since reportedly claimed that approximately 623GB of RingCentral data was compromised. However, this figure has not been independently verified, and the full contents of the allegedly obtained data have not been publicly confirmed.
Has the RingCentral breach been confirmed?
RingCentral has now confirmed that it was targeted by what it describes as a sophisticated social-engineering campaign.

SOURCE: https://www.ringcentral.com/trust-center/security-bulletin.html
According to the company, it took action to stop the unauthorised activity and began an investigation with assistance from a third-party forensic firm. RingCentral says the incident affected data belonging to a limited portion of its customers and that those affected are being contacted directly.
The company has also stated that its core RingCentral platform was not affected and that its services continue to operate normally.
While RingCentral’s statement confirms that unauthorised activity occurred, it does not confirm ShinyHunters’ claim that 623GB of data was obtained. The amount and exact type of information allegedly compromised should therefore continue to be treated as an unverified cybercriminal claim.

GoSafe is monitoring the situation
GoSafe will continue monitoring the incident for further developments, including additional information from RingCentral, details about the affected data and any publication of the files allegedly obtained by ShinyHunters.
Businesses using RingCentral should remain alert to suspicious emails, unexpected password-reset requests, impersonation attempts and targeted phishing messages.
Customers contacted by RingCentral should follow the company’s instructions and review any connected accounts, credentials or integrations that may be affected.
This article will be updated as further verified information becomes available.
PREVIOUSLY
RingCentral has been named in a new extortion claim published by the ShinyHunters cybercriminal group.
The listing appeared on 27 July 2026 and claims that RingCentral data has been compromised. ShinyHunters has given the company until 30 July 2026 to respond before it allegedly publishes the information. However, the listing does not specify the amount or type of data claimed to have been obtained.
Has the RingCentral breach been confirmed?
At the time of writing, no supporting files or detailed evidence have been publicly included with the claim.
RingCentral has also not published a statement about the allegation on its public security bulletin page. The incident should therefore be treated as an unverified cybercriminal claim, rather than a confirmed data breach.
Claims published on data leak sites do not independently prove that an organisation’s systems were successfully compromised. Further details may emerge if RingCentral issues a statement or ShinyHunters releases evidence supporting its allegations.

GoSafe is monitoring the situation
GoSafe will continue monitoring the RingCentral claim for further developments, including any official confirmation, information about the affected data or publication of the alleged files.
Businesses using RingCentral should remain alert to suspicious emails, unexpected password-reset requests and phishing attempts while the situation develops.
This article will be updated when further verified information becomes available.