High

RingCentral Breach: 1.6M Emails, Names, Phone Numbers (2026)

By Yazoul AI · automated

In July 2026, the cloud-based business communications platform RingCentral was the target of a ShinyHunters "pay or leak" extortion campaign . The group subsequently published data they claimed was obtained from the platform, which included 1.6M unique email addresses along with names, physical addr...

Overview

On July 2026, the cloud-based business communications platform RingCentral disclosed a data breach affecting 1,596,490 accounts. The ShinyHunters threat group, known for extortion-based attacks, published the data after a “pay or leak” campaign. The exposed information includes email addresses, names, phone numbers, and physical addresses. RingCentral has stated the incident affected “a limited portion of RingCentral customers” and is directly notifying those impacted.

What Was Exposed

The leaked dataset contains four distinct data types, each carrying different levels of risk:

  • Email addresses - These are your primary login identifier for countless services. Combined with the other data points, they enable targeted phishing campaigns.
  • Names - Full names allow attackers to personalize scams, making phishing emails far more convincing.
  • Phone numbers - These enable SMS phishing (smishing) and SIM-swapping attempts, which can compromise accounts secured by SMS two-factor authentication.
  • Physical addresses - This data enables physical mail fraud, utility scams, and more convincing social engineering.

Notably, passwords and financial data were not part of this leak. That distinction is important, as it shifts the primary risk from direct account takeover to identity-based social engineering.

Who’s Actually Affected

RingCentral is a business communications platform, meaning the data may belong to both business accounts and individual users. While RingCentral frames this as “a limited portion” of customers, 1.6 million accounts is substantial. If you’ve ever used RingCentral for work or personal communications, you may be affected. The company’s disclosure also doesn’t clarify whether the data came from primary accounts, sub-accounts, or contact lists, which could widen the actual impact.

How the Breach Happened

The ShinyHunters group operates on a “pay or leak” model. They infiltrate systems, exfiltrate data, then demand payment in exchange for not publishing. When negotiations fail, the data hits public forums. RingCentral has not disclosed the initial attack vector, but this pattern suggests the data was likely obtained through compromised credentials, a misconfigured system, or a third-party vendor - common entry points for this group.

How to Check If You’re Affected

Head to Have I Been Pwned and search your email address. If you appear in the breach, your data is in the leaked dataset. You can also watch for direct notification from RingCentral, which they’ve committed to sending to affected customers.

Recommendations

Given the data exposed, your priorities should be:

  1. Be skeptical of unexpected communications - Attackers now have your name, email, phone number, and address. Expect personalized phishing emails and smishing texts that reference RingCentral or your company. Never click links in unsolicited messages. Verify through official channels directly.

  2. Strengthen your phone-based security - Your phone number is now public. If you use SMS for two-factor authentication on sensitive accounts, consider switching to an authenticator app like Google Authenticator or a hardware key like a YubiKey. This protects against SIM-swapping attacks.

  3. Watch for mail fraud - Your physical address is exposed. Be alert for unexpected packages, utility bills, or governmental notices. Criminals can use this data for account opening fraud or to establish a false identity in your name.

  4. Monitor account activity - Regularly check your email and financial accounts for unfamiliar activity. Given the absence of passwords, the risk of direct account takeover is low, but the data supports identity fraud.

  5. Educate your team - If this affects your business, inform employees who may have communicated with RingCentral accounts. Ensure your organization’s security awareness program covers the specific phishing scenarios enabled by this data.

Security Insight

The RingCentral breach is another entry in a troubling pattern of business communications platforms becoming high-value targets for extortion groups like ShinyHunters. The “pay or leak” methodology is particularly aggressive because it creates a race between the company’s response and the public release of data. For a B2B communications provider, a breach of this nature also exposes the supply chain to their clients. The absence of passwords in this leak is cold comfort, but it does narrow the attack surface. More importantly, this incident underlines that any data collected across a widely-used platform can become ammunition for social engineering campaigns, often with the potential to impact the company even after the immediate breach is resolved.

Further Reading

Investigate Breaches Safely with NordVPN

Researching exposed data, paste sites, or threat actor infrastructure? Route your OSINT traffic through a VPN to avoid attribution and keep your investigation IP separate from your corporate network.

Get NordVPN for Research

Affiliate link — we may earn a commission at no extra cost to you.

Share:

Never miss a data breach report

Get real-time security alerts delivered to your preferred platform.

Related Breach Reports

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.