RingCentral Data Breach Exposes 1.6M Users in ShinyHunters Attack
The personal information of approximately 1.6 million individuals has been compromised in a data breach targeting cloud communications giant RingCentral, according to notifications and reports from SecurityWeek. The incident, which occurred in July 2025, stemmed from a "sophisticated social engineering campaign" that allowed attackers to infiltrate RingCentral's environment. In its public disclosure, RingCentral confirmed it engaged a leading third-party forensic firm to investigate and contained the unauthorized activity, adding that "services continue to operate without disruption" and the core platform was unaffected.
The ShinyHunters extortion group claimed responsibility for the attack, listing RingCentral on its Tor-based leak site and alleging the theft of more than 623 gigabytes of data. After RingCentral declined to meet the group's ransom demands, ShinyHunters published a 280GB archive containing the stolen records. The leaked dataset, which was subsequently added to Troy Hunt's HaveIBeenPwned database on Thursday, includes roughly 1.6 million unique email addresses paired with customer names, physical addresses, and phone numbers. RingCentral has not publicly confirmed the attacker's identity or the precise scope of impacted accounts.
Security researchers note that social engineering-driven breaches often bypass traditional perimeter defenses by exploiting human trust rather than software vulnerabilities. Organizations using RingCentral's unified communications, team messaging, or contact center services should treat the disclosure as a priority, particularly given the exposure of contact data that can fuel follow-on phishing and business email compromise campaigns. Affected users are urged to verify their exposure using an email breach checker, update any credentials reused across services with a password checker, and run a broader privacy checkup to assess residual digital exposure.
RingCentral has begun directly notifying impacted customers, noting that only a limited subset of its user base was affected. The company's incident response team emphasized that no further unauthorized activity has been detected since containment, though security professionals recommend that organizations monitor for credential-stuffing attempts and social engineering lures referencing RingCentral in the coming weeks.