RingCentral, the cloud communications provider, discovered on 28 July 2026 that an attacker had taken customer account data. The route reported is voice phishing: someone telephoned an employee posing as internal IT support and directed them to a page that harvested their credentials. On 13 August, after the company declined to pay, ShinyHunters published an archive reported at 280GB compressed, and Have I Been Pwned added the breach with 1.6 million accounts — names, email addresses, phone numbers and physical addresses.
The platform itself — calls, messages, meetings — continued operating throughout, and the company says core services were not affected. The exposure is the customer relationship layer: who uses the service and how to reach them.
The Same Call, Again
An IT-support impersonation against an employee is the identical opening move filed at 26-0526, where a vishing call reached 4.9 million Charter customer accounts, and across the 2025 retail wave. The target changes; the script does not. A caller with a plausible pretext asks a person to do something their job normally requires, and the credential does the rest.
A communications provider makes an instructive victim for it, because its business is trust in exactly the channels the technique abuses. Nothing in the reported route touched the platform’s engineering. The company was reached the way its own customers are reached.
Six Hundred Claimed, Two Hundred And Eighty Published
ShinyHunters initially claimed more than 623GB. What appeared was 280GB compressed. Both numbers came from the same party, weeks apart, and the gap between them is a working example of the rule this database applies to attacker figures everywhere: a volume claim is negotiation pressure, and it costs nothing to overstate.
The number worth keeping is neither. It is the 1.6 million accounts verified by an independent third party after publication — the same verification gap recorded at 26-0425, where ten million claimed became five and a half million confirmed.
Refusal, Priced
The company refused, and the data was published about a week later. For contact records, that trade is usually right: payment buys an unverifiable deletion promise from a party whose business is breaking promises, and the fields involved — names, addresses, phone numbers — were already widely circulated in other corpora. What refusal costs is a wave of convincing phishing against the people in the file, and they, rather than the refusing company, absorb it.
Compiled from company statements as reported, the Have I Been Pwned entry and contemporaneous coverage, listed below. The vishing route is as reported; the 623GB figure is the attackers’ claim and is carried as one. The 1.6 million count is HIBP’s verification of the published data. Graded high. Corrections: corrections@forensicpost.com.
- RingCentral data breach exposed info of 1.6 million accountsBleepingComputer
- 1.6M RingCentral accounts’ data dumped after ShinyHunters extortion attackThe Register
- 1.6 Million Likely Impacted by RingCentral Data BreachSecurityWeek
- RingCentral Data BreachHave I Been Pwned