Skip to content
News briefSC-2026-0312

RingCentral breach reaches 1.6 million accounts

Have I Been Pwned put a number on a July incident the vendor described only as sophisticated social engineering.

2 minEnterprise CyberSec

The scale of the RingCentral breach became public on 14 August, when Have I Been Pwned confirmed 1.6 million affected accounts. The exposed records contain names, email addresses, telephone numbers and physical addresses.

RingCentral disclosed the incident on 28 July, a day after the ShinyHunters extortion group claimed responsibility publicly. The company attributed it to a sophisticated social engineering campaign and has not described the entry point further. It also stated that the core platform was not affected and that services continued without disruption.

The group claims to have taken 623GB and to have published 280GB after the ransom was refused. RingCentral has not confirmed that attribution, though the claims line up with what Have I Been Pwned found.

Why the gap matters

Two and a half weeks separate the vendor's disclosure from a public count of affected accounts. For a security team, that gap is the operative detail: notification arrived long before the number that determines how many customer records need handling, and it came from a third party rather than the vendor.

The described vector is also worth noting. Social engineering against a support or identity process leaves no malware to detect and no vulnerability to patch. Controls built around endpoint detection do not engage, and the incident surfaces at the point where the data appears elsewhere.

Retold from BleepingComputer. This is a summary in our own words; follow the link for the original reporting.

Read next

Across the network

Desks that share a zone with this one on the BITBRIEF coverage map.

Terms defined