The cloud phone, messaging and contact center vendor disclosed a "sophisticated social engineering" campaign on July 28, but declined to pay; the breach tracking service Have I Been Pwned now counts ~1.6M dumped records.
ShinyHunters published roughly 280 GB of RingCentral customer data on its dark-web leak site this week, as first reported by The Register, after the cloud phone and contact-center vendor declined to pay an extortion demand. The dump, analyzed by Have I Been Pwned, contained about 1.6 million unique email addresses, each tagged with a name, a physical address, and a phone number.
The intrusion that produced it was not a software flaw. RingCentral disclosed the underlying incident on July 28 via its trust-center bulletin, attributing it to a "sophisticated social engineering campaign" that the company said hit a "limited portion" of its 600,000+ business customers and that the core platform was not impacted. Affected individuals were notified directly, the company added.
That is the mechanism. It is also the playbook. ShinyHunters added RingCentral to its Tor-based leak site on July 27, claiming theft of 623 GB of data, according to SecurityWeek. When RingCentral did not pay, the group published the ~280 GB compressed archive about a week later. HIBP's framing of the incident: "In July 2026, the cloud-based business communications platform RingCentral was the target of a ShinyHunters 'pay or leak' extortion campaign."
Social engineering is the load-bearing entry point for ShinyHunters in 2026. The group has run the same vendor-targeting approach against Salesforce customers via the Salesloft Drift integration (claiming more than 1.5 billion records), against Snowflake tenants through a compromised SaaS integrator, and against more than 100 organizations via an Oracle PeopleSoft zero-day, BleepingComputer reports. RingCentral is the first major unified-communications and contact-center vendor on that list. The category is not new. The vendor on the list is.
The exposed fields cover four things: a name, a physical address, a phone number, and the 1.6 million unique email addresses that tie them together. Those fields are useful for targeted phishing and credential-stuffing rather than for direct call or message interception. RingCentral's bulletin, the HIBP entry, and independent press coverage all converge on that scope. There is no public evidence in the source basis that the leak includes call recordings, message content, or stored credentials.
The "limited portion" framing RingCentral used is true at the customer-account level: the company serves more than 600,000 businesses, and the records touch a fraction of those tenants. The 1.6 million figure is true at the individual-record level. Both are accurate; neither is the whole picture, and the gap between them is where the incident's real pressure sits.
IT and security teams with admin access to a RingCentral tenant should treat the dumped email list as a credential-stuffing clock that started when the archive went up. Credentials that appeared in the dump need to be rotated, especially where they were reused across services. OAuth tokens and SSO integrations that inherit RingCentral admin scope need to be audited and re-issued. Support inboxes and end-user phishing reports need to be watched for targeted lures built from the name, address, and phone triplet the dump now provides. Contact-center teams handling inbound calls should brief agents to expect socially engineered callers claiming to be RingCentral support, since phone and name are exactly the pretext the dump enables.
ShinyHunters' 280 GB release covers about 45% of the 623 GB the group claimed on July 27. The other 343 GB is the variable that determines whether this is a one-release incident or the first of two.