ShinyHunters leaks 1.6M RingCentral email addresses

RingCentral disclosed on July 28, 2026 that it had been hit by "a sophisticated social engineering campaign" affecting a "limited portion" of its customers. The comms platform said it detected the intrusion, stopped the unauthorized activity, brought in a third-party forensic firm, and has seen no further unauthorized activity since. RingCentral did not name an attacker and did not respond to a request for comment from The Register.
The extortion gang ShinyHunters had already claimed the breach on its data leak site, with screenshots circulating on social media. The group said it stole more than 623 GB of data and gave RingCentral a July 30 deadline to pay. RingCentral apparently did not pay, and on August 3 ShinyHunters wrote: "The company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care." The group then posted the stolen customer details online. According to Have I Been Pwned, the dump contains 1.6 million unique email addresses tied to RingCentral, along with names, physical addresses, and phone numbers.
A ShinyHunters spokesperson told The Register that the group got in by voice-phishing a RingCentral employee into handing over their password, rather than through a technical exploit.
Security researcher Dominic Alvieri called ShinyHunters his "top threat group and probably is for most analysts." The Register notes the gang has hacked hundreds of organizations since the start of the year, including education-technology firms serving schools and universities, and healthcare organizations. As a separate example of that pattern, the article cites ShinyHunters' recent dump of data from Abbott's cancer diagnostics business: 10.9 million unique email addresses plus personal and health information, which the crooks claim includes more than 30 million rows of customer data, over one million Social Security numbers, 7.5 million dates of birth, 22 million-plus rows of doctor-patient client notes, and more than 20 million medical-order records. Those Abbott figures are cited only as context for ShinyHunters' broader activity; they are not part of the RingCentral breach.
Key facts
- ShinyHunters leaked 1.6 million unique email addresses tied to RingCentral, along with names, physical addresses, and phone numbers, after RingCentral missed a July 30 payment deadline.
- RingCentral disclosed the breach on July 28, 2026, attributing it to a social engineering campaign affecting a limited portion of customers, and has not publicly named the attacker.
- A ShinyHunters spokesperson said the group got in by voice-phishing a RingCentral employee out of their password, and the gang claims it took more than 623 GB of data.
- ShinyHunters posted a statement on August 3 saying RingCentral refused to reach an agreement despite the group's offers.
- The article also cites, as separate context, ShinyHunters' earlier dump of Abbott cancer diagnostics data: 10.9 million email addresses and health-related records, unrelated to the RingCentral breach.
Why it matters
The breach shows a well-resourced extortion crew reaching a major business communications platform not through a software exploit but by talking a single employee out of their password. RingCentral, which handles calls, messaging, and video for large numbers of businesses, becomes a fresh case in a wave of ShinyHunters attacks that the article says has hit hundreds of organizations this year, spanning education technology and healthcare as well as communications.
Who it affects
RingCentral customers whose email addresses, names, physical addresses, and phone numbers are now circulating publicly are the direct victims; the leak gives scammers ready-made material for phishing or impersonation attempts referencing RingCentral. The article does not say the leak includes passwords or payment details.
How to use it
Anyone who uses RingCentral can check whether their email address appears in the leak through Have I Been Pwned, watch for phishing messages that reference RingCentral or invoke the breach, and treat unsolicited calls or emails claiming to be from RingCentral with extra caution given that the attackers themselves got in through a phone-based social engineering trick.
How solid is it
The account rests on RingCentral's own public statement, a ShinyHunters leak-site post and spokesperson comment obtained directly by The Register, and the Have I Been Pwned figure for leaked email addresses; the reporter, Jessica Lyons, attempted to reach RingCentral for comment. The attribution to ShinyHunters comes from the gang's own claims and screenshots, not from RingCentral confirming an attacker.
Risks and caveats
RingCentral has not named ShinyHunters or any attacker, so the attribution rests on the extortion gang's own statements. The source gives no dollar figure for the ransom ShinyHunters demanded, and does not independently confirm a total count of affected individuals beyond the 1.6 million unique email addresses. The much larger numbers around Social Security numbers, dates of birth, and medical records belong to the separate Abbott breach, not to RingCentral, and should not be read as part of this incident.
“The company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care.”
— ShinyHunters, public statement, August 3, 2026