In July 2026, cloud communications provider RingCentral was hit by a ShinyHunters “pay or leak” extortion campaign. After the demand, the group published data they attributed to the platform, containing roughly 1.6 million unique email addresses along with names, physical addresses and phone numbers. RingCentral characterized the impact as affecting a limited portion of its customer base and said it was contacting those affected directly.
While the exposed data does not appear to include passwords, the combination of verified emails, names, phone numbers and physical addresses is a strong foundation for targeted phishing, smishing and social-engineering attacks — including help-desk impersonation and MFA-fatigue attempts against corporate identity systems.
What to take away: organizations using RingCentral should treat affected users as elevated phishing targets, reinforce verification procedures for password/MFA reset requests, and monitor for credential-stuffing or account-takeover attempts leveraging the leaked contact details.