RingCentral disclosed that it was targeted in a ShinyHunters "pay or leak" extortion campaign, and data allegedly stolen in the intrusion was later published by the threat actor. The exposed dataset reportedly contains about 1.6 million unique email addresses along with customer names, phone numbers, and physical addresses, with the breach dated 2026-07-27 in public reporting.
RingCentral said the incident affected only a limited portion of its customers and that it was contacting impacted parties directly. The publication of contact and identity data raises immediate risks of targeted phishing, identity theft, and other abuse of personal information for affected customers.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
HaveIBeenPwned added the leaked RingCentral data to its database on Thursday and said the dataset contains about 1.6 million unique email addresses. It also reported that the leaked records include names, physical addresses, and phone numbers.
After setting a July 30 extortion deadline, ShinyHunters allegedly published RingCentral customer details online on August 3, saying the company failed to reach an agreement. The dumped data reportedly included email addresses, names, physical addresses, and phone numbers.
On July 28, 2026, RingCentral disclosed that its systems were compromised in a sophisticated social engineering campaign. The company said it had remediated the incident, had not seen new unauthorized activity afterward, and that core services were not disrupted.
In July 2026, RingCentral was targeted in a ShinyHunters "pay or leak" extortion campaign. One source lists the breach date as 2026-07-27.
In its disclosure notice, RingCentral said the incident affected only a limited portion of its customers. The company also said it was contacting impacted customers directly.
After the intrusion, ShinyHunters published data it claimed to have obtained from RingCentral. The exposed dataset reportedly contained about 1.6 million unique email addresses, plus names, phone numbers, and physical addresses.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcetheregister.com
Open sourcebleepingcomputer.com
Open sourcesecurityweek.com
Open sourcehookphish.com
Open sourcehaveibeenpwned.com
Open sourceringcentral.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.