• August 10, 2026

In July 2026, RingCentral, a major provider of cloud-based business communications, confirmed that a sophisticated social-engineering campaign had resulted in unauthorised access to data associated with a limited number of its customers. The ShinyHunters extortion group claimed responsibility for the incident and reportedly alleged that approximately 623GB of information had been compromised, threatening to publish the data if the company failed to respond. RingCentral says it quickly contained the unauthorised activity and launched an investigation with assistance from an external forensic specialist. The company is contacting affected customers directly and has stated that its core communications platform was not compromised, with phone, messaging, video and other services continuing to operate without disruption.

  • Breach date: 2026-08-03
  • Persons affected: 3,163,477

Data exposed: Address, Email, Name, Phone

Potential risks

The exposed information could be used to support targeted phishing attacks, account impersonation, business email compromise and other forms of social engineering. Customer or support records may help attackers create convincing messages that appear to come from RingCentral or a trusted business contact. Depending on the information compromised, affected organisations may also face an increased risk of credential theft, fraud, unauthorised account access and further attempts to compromise employees or connected systems.