RingCentral Breach: 1.6M Emails, Names, Phone Numbers (2026)
In July 2026, the cloud-based business communications platform RingCentral was the target of a ShinyHunters "pay or leak" extortion campaign . The group subsequently published data they claimed was obtained from the platform, which included 1.6M unique email addresses along with names, physical addr...
Overview
On July 2026, the cloud-based business communications platform RingCentral disclosed a data breach affecting 1,596,490 accounts. The ShinyHunters threat group, known for extortion-based attacks, published the data after a “pay or leak” campaign. The exposed information includes email addresses, names, phone numbers, and physical addresses. RingCentral has stated the incident affected “a limited portion of RingCentral customers” and is directly notifying those impacted.
What Was Exposed
The leaked dataset contains four distinct data types, each carrying different levels of risk:
- Email addresses - These are your primary login identifier for countless services. Combined with the other data points, they enable targeted phishing campaigns.
- Names - Full names allow attackers to personalize scams, making phishing emails far more convincing.
- Phone numbers - These enable SMS phishing (smishing) and SIM-swapping attempts, which can compromise accounts secured by SMS two-factor authentication.
- Physical addresses - This data enables physical mail fraud, utility scams, and more convincing social engineering.
Notably, passwords and financial data were not part of this leak. That distinction is important, as it shifts the primary risk from direct account takeover to identity-based social engineering.
Who’s Actually Affected
RingCentral is a business communications platform, meaning the data may belong to both business accounts and individual users. While RingCentral frames this as “a limited portion” of customers, 1.6 million accounts is substantial. If you’ve ever used RingCentral for work or personal communications, you may be affected. The company’s disclosure also doesn’t clarify whether the data came from primary accounts, sub-accounts, or contact lists, which could widen the actual impact.
How the Breach Happened
The ShinyHunters group operates on a “pay or leak” model. They infiltrate systems, exfiltrate data, then demand payment in exchange for not publishing. When negotiations fail, the data hits public forums. RingCentral has not disclosed the initial attack vector, but this pattern suggests the data was likely obtained through compromised credentials, a misconfigured system, or a third-party vendor - common entry points for this group.
How to Check If You’re Affected
Head to Have I Been Pwned and search your email address. If you appear in the breach, your data is in the leaked dataset. You can also watch for direct notification from RingCentral, which they’ve committed to sending to affected customers.
Recommendations
Given the data exposed, your priorities should be:
-
Be skeptical of unexpected communications - Attackers now have your name, email, phone number, and address. Expect personalized phishing emails and smishing texts that reference RingCentral or your company. Never click links in unsolicited messages. Verify through official channels directly.
-
Strengthen your phone-based security - Your phone number is now public. If you use SMS for two-factor authentication on sensitive accounts, consider switching to an authenticator app like Google Authenticator or a hardware key like a YubiKey. This protects against SIM-swapping attacks.
-
Watch for mail fraud - Your physical address is exposed. Be alert for unexpected packages, utility bills, or governmental notices. Criminals can use this data for account opening fraud or to establish a false identity in your name.
-
Monitor account activity - Regularly check your email and financial accounts for unfamiliar activity. Given the absence of passwords, the risk of direct account takeover is low, but the data supports identity fraud.
-
Educate your team - If this affects your business, inform employees who may have communicated with RingCentral accounts. Ensure your organization’s security awareness program covers the specific phishing scenarios enabled by this data.
Security Insight
The RingCentral breach is another entry in a troubling pattern of business communications platforms becoming high-value targets for extortion groups like ShinyHunters. The “pay or leak” methodology is particularly aggressive because it creates a race between the company’s response and the public release of data. For a B2B communications provider, a breach of this nature also exposes the supply chain to their clients. The absence of passwords in this leak is cold comfort, but it does narrow the attack surface. More importantly, this incident underlines that any data collected across a widely-used platform can become ammunition for social engineering campaigns, often with the potential to impact the company even after the immediate breach is resolved.
Further Reading
Investigate Breaches Safely with NordVPN
Researching exposed data, paste sites, or threat actor infrastructure? Route your OSINT traffic through a VPN to avoid attribution and keep your investigation IP separate from your corporate network.
Get NordVPN for ResearchAffiliate link — we may earn a commission at no extra cost to you.
Never miss a data breach report
Get real-time security alerts delivered to your preferred platform.
Related Breach Reports
In August 2026, the Alcon eye care company was named in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published data allegedly sourced from Alcon containing 218k unique email addresses along with other largely corporate B2B contact fields, including name, phone number and ...
In June 2026, Inter-Con Security was targeted in a ShinyHunters “pay or leak” extortion campaign . The group subsequently published data it alleged was taken from the company, including 276k unique email addresses along with names, physical addresses, job titles and phone numbers. The data encompass...
In July 2026, electronic test and measurement equipment company Fluke was targeted in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published more than 100GB of data allegedly taken from the company. The corpus contained largely corporate contact information, including ove...
In June 2026, a party claiming to have access to data from Goose Creek Candle Company sent emails to a number of the company's customers , claiming the company had a security vulnerability and suffered a data breach. The data was subsequently sent to Have I Been Pwned and contained 6.6M unique email...