Overview
- RingCentral detected an intrusion in July that it called a “sophisticated social engineering campaign” and publicly disclosed the incident on July 28 while starting a forensic investigation and remediation.
- Have I Been Pwned analyzed the leaked archive and confirmed it holds roughly 1.6 million unique account records including names, email addresses, phone numbers and physical addresses.
- The ShinyHunters extortion group added RingCentral to its Tor leak site in late July claiming it stole about 623 GB and later published a 280 GB compressed archive after RingCentral did not pay.
- RingCentral says its core platform continued to operate, that affected customers were being notified directly, and that a third‑party forensic firm has been engaged with no further unauthorized activity observed since remediation.
- The exposed contact data raises a clear risk of targeted phishing and fraud for customers and partners and increases pressure on RingCentral to disclose how attackers gained access and to provide a detailed root‑cause report.