started · updated
RingCentral data breach exposes 1.6 million accounts
RingCentral, a global cloud communications provider, has suffered a major data breach affecting approximately 1.6 million unique email addresses and associated accounts. The incident, attributed to a sophisticated social engineering campaign, was claimed by the cybercriminal group ShinyHunters.
Following a refusal by RingCentral to negotiate or pay an extortion demand, the hackers published a 280 GB compressed file containing internal infrastructure data on a dark web forum. The authenticity of the leaked database has been verified by the security monitoring service Have I Been Pwned.
The exposed information includes full names of users and employees, corporate and personal email addresses, direct phone numbers, virtual extensions, and physical addresses. While RingCentral stated the attack affected only a limited fraction of its customer base and that its core cloud services remained operational, the breach highlights the significant risks posed by attacks targeting SaaS platforms.