1.6 million RingCentral accounts dumped online after ShinyHunters extortion attempt fails
The group says it stole 623GB through a social engineering campaign in July and released a 280GB archive once RingCentral refused to pay.
RingCentral disclosed on July 28 that its systems had been compromised through what it described as a sophisticated social engineering campaign. Roughly three weeks later, the consequences of that refusal to pay became public: a leaked archive covering personal information from 1.6 million accounts.
Have I Been Pwned analyzed the dump and confirmed it contains names, email addresses, phone numbers and physical addresses tied to 1.6 million RingCentral customers. The company has said the breach did not reach its core communications platform and that services continued operating without disruption throughout.
ShinyHunters, the extortion group behind the attack, claims it exfiltrated 623 gigabytes of data in total during the July intrusion. When RingCentral declined to pay, the group published a compressed 280 gigabyte file, a fraction of the full claimed haul, which is a common tactic: release enough to prove the theft was real and force the sting of public exposure, while keeping the rest as leverage or for a later sale.
RingCentral disclosed on July 28 that its systems had been compromised through what it described as a sophisticated social engineering campaign.
RingCentral says that upon detecting the unauthorized activity it moved to shut it down and brought in a third-party forensics firm to investigate, and that it has not observed any further unauthorized activity since. The company has not detailed exactly how the social engineering campaign reached its systems in the first place, though the phrase itself, in nearly every recent case tied to this group, has meant a phone call to a help desk rather than a phishing email.
What makes this one worth tracking past the headline number is the pattern it fits into. RingCentral joins a growing list of companies, McKesson among the most recent, hit by the same cluster of tactics this year: voice-based social engineering against support staff, followed by a public leak once ransom demands go unanswered. The technical sophistication is minimal. The success rate, unfortunately, keeps holding up.
RingCentral's own position makes the data slightly more sensitive than a typical customer database. As a unified communications provider, the company sits on call metadata, contact directories and business phone infrastructure for a large base of small and mid-sized companies that route their day-to-day calls and messages through its platform. Names, emails and phone numbers alone will not unlock anyone's voicemail, but that kind of contact data is exactly what feeds the next round of vishing calls, against RingCentral's own customers this time, closing a loop that this industry has been watching tighten all year.
Based on reporting by BleepingComputer.




