CAROLINAS LEADER IN TECHNOLOGY
OFFICES IN: CHARLOTTESPARTANBURGCHARLESTON

RingCentral Data Breach: 1.6 Million Accounts Reportedly Exposed

RingCentral Data Breach

RingCentral is facing scrutiny after a social engineering attack reportedly exposed personal information connected to approximately 1.6 million accounts.

The cloud-based business communications provider confirmed that it was targeted in what it described as a sophisticated social engineering campaign. While RingCentral says its core platform was not affected, subsequent reporting indicates that names, email addresses, phone numbers, and physical addresses may have been accessed and published online.

For businesses, the incident raises important questions about how customer information is protected, how quickly affected organizations are notified, and how a breach involving a major technology provider can create risks beyond the provider’s own network.

What RingCentral Has Confirmed

RingCentral published a general security advisory on July 28, 2026. The company said it had recently discovered that it was the target of a sophisticated social engineering campaign.

According to RingCentral, it stopped the unauthorized activity and began an investigation with help from a third-party forensic firm. The company said it had not observed additional unauthorized activity after taking corrective action. RingCentral described the impact as limited to data associated with a portion of its customers and said it was contacting those customers directly. Its core platform was not affected, and services continued without disruption.

Where the 1.6 Million Figure Comes From

On August 13, 2026, breach notification service Have I Been Pwned added the incident to its database after reviewing information published by the attackers. It identified approximately 1.6 million unique email addresses in the dataset. The exposed information reportedly also included names, physical addresses, and phone numbers.

As of August 15, RingCentral had not publicly confirmed that 1.6 million people were affected. It had also not verified the full volume of data allegedly stolen. The number should therefore be understood as an estimate based on independent analysis of the published information, not a final count announced by RingCentral.

Public reporting has attributed the incident to the ShinyHunters extortion group, which claimed it stole more than 623 gigabytes of data. RingCentral has not publicly attributed the attack to ShinyHunters or confirmed that figure.

The attackers also reportedly claimed that they gained access by voice-phishing an employee and convincing that person to reveal a password. RingCentral has confirmed that social engineering was involved, but it has not publicly confirmed the specific method used.

What Information Was Reportedly Exposed?

Have I Been Pwned identified the following information in the published dataset:

  • Names
  • Email addresses
  • Phone numbers
  • Physical addresses

Its public entry does not list passwords, Social Security numbers, or financial information among the exposed categories. That does not necessarily provide a complete picture of every file involved. Even without those details, this combination of contact information can help criminals create convincing emails, text messages, and phone calls.

Why Follow-Up Scams Are a Concern

After a widely reported breach, criminals often take advantage of the confusion. Employees may receive messages or calls claiming to come from RingCentral, an IT provider, or an internal administrator. They may be asked to reset a password, review a voicemail, install an update, or provide a multifactor authentication code. Because the attacker may already possess accurate personal details, the request can appear legitimate. Leaked information may be reused in phishing, voice phishing, business email compromise, and account takeover attempts.

What RingCentral Customers Should Do

RingCentral says it is notifying affected customers directly. Businesses should review any notice carefully, but employees should avoid clicking links or calling numbers in unexpected messages.

Organizations should also consider the following precautions:

  1. Warn employees about breach-related phishing and phone scams.
  2. Require strong, unique passwords and multifactor authentication for communications and administrator accounts.
  3. Never approve an unexpected authentication request or give a one-time code to a caller.
  4. Review administrator access, recent activity, integrations, forwarding settings, and unexpected configuration changes.
  5. Report suspicious messages or calls to the IT or security team before responding.

Individuals can also use Have I Been Pwned to check whether an email address appears in the published dataset. A match means the address was found in the data reviewed by the service, but it does not replace direct communication from RingCentral or a formal investigation.

What This Breach Means for Other Businesses

The RingCentral incident is a reminder that cybersecurity is not limited to firewalls, antivirus software, and software patches. Social engineering targets people and the business processes they trust. One convincing phone call may be enough to bypass otherwise strong technical safeguards.

It also shows why businesses must pay attention to third-party risk. Technology vendors may hold information that becomes useful to attackers, even when their primary services remain available.

The goal is not to panic every time a major provider reports an incident. The goal is to be prepared. Businesses should know which vendors store sensitive information, who receives security notices, and how the organization will respond. Employee awareness training, multifactor authentication, limited administrator access, and a documented incident response plan can all help prevent one breach from leading to another.

Incidents like this are also a good reminder to consider who manages your business communications and what kind of support is available when questions arise. If your business is exploring other options, TotalBC’s CallNet VoIP provides a locally supported alternative backed by a team you can reach when you need help. Contact TotalBC to learn more about making the switch. 

Scroll to Top