ShinyHunters Claims 1.6 Million Records Stolen from RingCentral
The extortion group published 280 gigabytes of alleged RingCentral data after the company refused to pay. Names, addresses, phone numbers and email addresses are now circulating freely.

Key points
- ShinyHunters, a prolific extortion group, claims to have stolen more than 623 gigabytes of data from business communications company RingCentral in July 2025.
- RingCentral says the breach was carried out through a "sophisticated social engineering campaign", meaning criminals manipulated people rather than purely exploiting software flaws.
- RingCentral refused to pay the ransom; ShinyHunters then published a 280-gigabyte archive of the stolen files publicly.
- Data breach tracker HaveIBeenPwned found approximately 1.6 million unique email addresses in the leaked data, alongside names, home addresses and phone numbers.
- RingCentral says only a limited number of customers were affected and that its core phone and messaging services were never disrupted.
RingCentral, a company that provides cloud-based phone systems, team messaging and video meetings to businesses worldwide, disclosed in July that criminals had broken into part of its systems using what it described as a "sophisticated social engineering campaign." Social engineering means criminals tricked or manipulated people, usually employees or contractors, into handing over access, rather than cracking a password by brute force or exploiting a software flaw.
The company says it caught the intrusion quickly, shut it down, and brought in a specialist forensics firm to investigate. No new unauthorised activity has been detected since.
Who carried out the attack?
ShinyHunters almost certainly did it. The group, which has been linked to major breaches at Ticketmaster and several other large companies, added RingCentral to its dark-web leak site, a password-protected website on the Tor network used to publish stolen data and pressure victims, in late July. It claimed to hold more than 623 gigabytes of RingCentral data and demanded payment.
RingCentral did not pay. About a week later, ShinyHunters published a 280-gigabyte archive of the alleged data for anyone to download.
RingCentral has not publicly confirmed that ShinyHunters carried out the attack, and as SecurityWeek first reported, the company has not yet confirmed the total number of people affected.
What information was exposed?
Personal details, not financial records or passwords, appear to be the main risk here.
| Data type | Detail |
|---|---|
| Email addresses | ~1.6 million unique addresses |
| Full names | Included |
| Home/work addresses | Included |
| Phone numbers | Included |
| Financial data | Not reported |
| Passwords | Not reported |
HaveIBeenPwned, a free website that lets people check whether their email address has appeared in any known data breach, added the leaked RingCentral records to its database on a Thursday in late July.
Should affected customers be worried?
If your email address appears in the leak, you did not lose your bank details or login credentials, but you are at higher risk of phishing, meaning criminals sending convincing fake emails, and spam phone calls.
RingCentral says it contacted everyone it believes was affected directly. If you did not receive a notification from the company, it says you were not caught up in the incident. That said, checking your email on HaveIBeenPwned costs nothing and takes thirty seconds.
Watch for unexpected emails claiming to be from RingCentral, your bank, or any service you use. Any message asking you to click a link and confirm your details deserves extra suspicion right now. Call the company back on a number you find yourself rather than one given in the email.



