Particle.news
Download on the App Store

RingCentral Leak Exposes Data From 1.6 Million Accounts

Have I Been Pwned’s analysis confirms the published files contain 1.6 million account records tied to a ShinyHunters dark‑web release.

Overview

  • RingCentral detected an intrusion in July that it called a “sophisticated social engineering campaign” and publicly disclosed the incident on July 28 while starting a forensic investigation and remediation.
  • Have I Been Pwned analyzed the leaked archive and confirmed it holds roughly 1.6 million unique account records including names, email addresses, phone numbers and physical addresses.
  • The ShinyHunters extortion group added RingCentral to its Tor leak site in late July claiming it stole about 623 GB and later published a 280 GB compressed archive after RingCentral did not pay.
  • RingCentral says its core platform continued to operate, that affected customers were being notified directly, and that a third‑party forensic firm has been engaged with no further unauthorized activity observed since remediation.
  • The exposed contact data raises a clear risk of targeted phishing and fraud for customers and partners and increases pressure on RingCentral to disclose how attackers gained access and to provide a detailed root‑cause report.