Filed under: Cybersecurity — Data Protection — August 2026
What happened
RingCentral, the phone and messaging platform used by more than 600,000 businesses, has confirmed that an extortion group called ShinyHunters broke in through a social-engineering attack in July and stole account data. This week that breach was confirmed to affect 1.6 million accounts, with names, email addresses, phone numbers, and physical addresses exposed. RingCentral refused to pay, and the group leaked a large batch of the stolen files publicly. Core calling and messaging service was not disrupted.
Why it matters to your business
If your business uses RingCentral for phones or voicemail, your account details may be in this leak — and we already flagged a phishing kit last week that impersonates RingCentral voicemail notifications to steal Microsoft 365 logins. That campaign just got more convincing: scammers now have real names, numbers, and addresses to make follow-up phishing calls or emails feel legitimate. Anyone whose contact info was exposed is a more attractive target for impersonation scams built around this breach.
What to do this week
Check whether your business email shows up at haveibeenpwned.com, change your RingCentral account password, and turn on multi-factor authentication under the RingCentral admin portal (Settings > Security > Multi-Factor Authentication) if it isn’t already required. Tell staff that any unexpected “RingCentral security alert” email, text, or phone call this month deserves extra scrutiny — verify through the official app or website rather than clicking a link or calling a number provided in the message. Watch for spear-phishing that references your real name, phone number, or address to seem trustworthy.
The bigger picture
A breach at a vendor you trust doesn’t stay contained to that vendor — stolen contact details become raw material for the next phishing campaign aimed at you and your customers. — RingCentral data breach exposed info of 1.6 million accounts
Want help checking if your team’s accounts show up in a breach like this? Book a free consult — https://micro1tech.com/contact/