ShinyHunters Claims 1.6 Million Records Stolen from RingCentral

The extortion group published 280 gigabytes of alleged RingCentral data after the company refused to pay. Names, addresses, phone numbers and email addresses are now circulating freely.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
A dark desktop workspace with multiple monitors displaying fragmented data streams and breach notifications, a phone sitting nearby suggesting communications in
Share

Key points

  • ShinyHunters claims to have stolen more than 623 gigabytes of data from business communications company RingCentral in July 2025.
  • RingCentral says the breach came through a "sophisticated social engineering campaign", meaning criminals manipulated people rather than exploiting software flaws.
  • RingCentral didn't pay the ransom; ShinyHunters then published a 280-gigabyte archive of the stolen files publicly.
  • Data breach tracker HaveIBeenPwned found approximately 1.6 million unique email addresses in the leaked data, alongside names, home addresses and phone numbers.
  • RingCentral says only a limited number of customers were affected and that its core phone and messaging services were never disrupted.

RingCentral, which provides cloud-based business phone, messaging and video services to companies worldwide, disclosed in July that criminals had broken into part of its systems through what it called a "sophisticated social engineering campaign." Social engineering means criminals tricked or manipulated employees or contractors into handing over access, rather than exploiting a software flaw.

The company says it caught the intrusion, shut it down, and brought in a specialist forensics firm. No new unauthorised activity has been detected since.

Who carried out the attack?

ShinyHunters added RingCentral to its dark-web leak site, a password-protected site on the Tor network used to publish stolen data and pressure victims, in late July. The group has been linked to major breaches at Ticketmaster and others; we've tracked it across 21 stories in the last 90 days, including July's Brinks Home incident where it threatened to publish 4.9 million Salesforce records. It claimed to hold more than 623 gigabytes of RingCentral data and demanded payment.

RingCentral didn't pay. Roughly a week later, ShinyHunters published a 280-gigabyte archive of the alleged data for anyone to download.

As SecurityWeek first reported, RingCentral hasn't publicly confirmed that ShinyHunters carried out the attack, nor confirmed the total number of people affected.

What information was exposed?

Personal details appear to be the main risk, not financial records or login credentials.

Data type Detail
Email addresses ~1.6 million unique addresses
Full names Included
Home/work addresses Included
Phone numbers Included
Financial data Not reported
Passwords Not reported

HaveIBeenPwned, a free site where anyone can check whether their email has appeared in a known breach, added the leaked RingCentral records to its database on a Thursday in late July.

Should affected customers be worried?

If your email address appears in the leak, you didn't lose bank details or login credentials, but you're at higher risk of phishing, meaning criminals sending convincing fake emails, and spam calls.

RingCentral says it contacted everyone it believes was affected. If you didn't get a notification, the company says you weren't caught up in it. Checking your email on HaveIBeenPwned costs nothing and takes thirty seconds.

Watch for unexpected emails claiming to be from RingCentral or any service you use. Any message asking you to click a link and confirm your details deserves extra suspicion right now. Call the company back on a number you find yourself, not one given in the email.

The pattern here is familiar: a social-engineering entry point, a slow-burn exfiltration, and a public dump when the victim refuses to pay. The data type matters less than the volume. 1.6 million contact records is a ready-made phishing list, and whoever downloads that archive doesn't have to be ShinyHunters to use it.

© 2026 Threat Vectr