[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f_ajHHPl4h0wMRV2zfpSBv78LgVPkqu3zdQ3Yws4KLZc":3},{"article":4,"iocs":40},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":27,"category":28,"article_tags":32},"140c582b-2706-411a-9c16-4db624bd2ec9","RingCentral data breach exposed info of 1.6 million accounts","ringcentral-data-breach-exposed-info-of-1-6-million-accounts-815fb6","The ShinyHunters extortion group stole personal information from 1.6 million RingCentral accounts after hacking the company in July, according to the data breach notification service Have I Been Pwned. [...]","The ShinyHunters extortion group has claimed responsibility for a data breach at RingCentral, a cloud-based communication platform. The group alleges to have stolen 623GB of data, including personal information for 1.6 million accounts, which they subsequently leaked on their dark web site after RingCentral refused to pay a ransom. Have I Been Pwned has confirmed the leaked data contains records such as names, email addresses, phone numbers, and physical addresses.","ShinyHunters group claims to have stolen data of 1.6 million RingCentral accounts.","RingCentral data breach exposed info of 1.6 million accounts By Sergiu Gatlan August 14, 2026 06:52 AM 0 The ShinyHunters extortion group stole personal information from 1.6 million RingCentral accounts after hacking the company in July, according to the data breach notification service Have I Been Pwned. RingCentral is a cloud-based collaboration and communication platform used by over 600,000 businesses for services such as calling, messaging, and voicemail. The company disclosed the incident on July 28, revealing that its systems were compromised following what it described as a \"sophisticated social engineering campaign.\" \"We have not seen any new unauthorized activity since taking these remediation efforts. To date, this incident has affected data for a limited portion of RingCentral customers, and we are communicating with affected customers directly,\" it noted. \"If you are not contacted by RingCentral, you are not affected. This incident did not impact the core RingCentral platform, and our services continue to operate without disruption.\" Although RingCentral has not attributed the breach to a specific threat actor or hacking group and has yet to share further details on the incident, the ShinyHunters extortion gang claimed responsibility on July 27, claiming they had stolen 623GB of data. RingCentral entry on ShinyHunters' data leak site (BleepingComputer) ​After the company refused to pay a ransom to have the stolen data destroyed, the cybercrime group leaked a compressed archive containing 280GB worth of files on their dark web leak site. While a RingCentral spokesperson didn't immediately reply when contacted by BleepingComputer to confirm ShinyHunters' claims, Have I Been Pwned confirmed the link after analyzing the leaked data and said on Thursday that it contained records for 1.6 million accounts, including names, email addresses, phone numbers, and physical addresses. \"In July 2026, the cloud-based business communications platform RingCentral was the target of a ShinyHunters 'pay or leak' extortion campaign,\" it said. Although RingCentral has yet to share exactly how the threat actors gained access to its systems, ShinyHunters has claimed breaches at hundreds of Salesforce customers over the past year, saying they've stolen over 1.5 billion records in Salesloft Drift and Salesforce Aura campaigns. The extortion group was also linked to security breaches at more than a dozen Snowflake customers, as well as various other third-party integration providers. Most recently, ShinyHunters claimed responsibility for a new series of breaches at over 100 organizations following data-theft attacks that exploited an Oracle PeopleSoft zero-day flaw. Once attackers have valid credentials, only 37% of their actions are blocked Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report Related Articles: Kodak confirms data breach claimed by ShinyHunters extortion gangCouncil of Europe investigates ShinyHunters data breach claimsInfinite Campus data breach affects 137,000 school staff accountsValve notifies Steam hardware customers of a data breachLevi Strauss & Co. says hackers stole corporate data in cyberattack","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fringcentral-data-breach-exposed-info-of-16-million-accounts\u002F","https:\u002F\u002Fwww.bleepstatic.com\u002Fcontent\u002Fhl-images\u002F2026\u002F08\u002F14\u002FRingCentral-headpic.jpg","2026-08-14T10:52:05+00:00","2026-08-14T12:00:18.642037+00:00",8,[18,21,24],{"name":19,"type":20},"RingCentral","vendor",{"name":22,"type":23},"ShinyHunters","threat_actor",{"name":25,"type":26},"Oracle PeopleSoft","product","2e06f76c-d5b9-4f54-9eef-4d3447b10730",{"id":27,"icon":29,"name":30,"slug":31},null,"Breaches","breaches",[33,35],{"category":34},{"id":27,"icon":29,"name":30,"slug":31},{"category":36},{"id":37,"icon":29,"name":38,"slug":39},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[41],{"type":42,"value":43,"context":44},"malware","Oracle PeopleSoft zero-day flaw","Exploited by ShinyHunters in other recent attacks."]