RingCentral Hit by ShinyHunters — 1.6 Million Accounts Exposed
RingCentral, a cloud-based business communications platform used by over 600,000 companies for calls, messaging, and voicemail, confirmed a breach after the ShinyHunters extortion group claimed responsibility and made good on their threat, according to Bleeping Computer.
The attackers got in through a social engineering campaign (manipulating people rather than breaking code — tricking employees into handing over access). From there, ShinyHunters claimed to have pulled 623GB of data. When RingCentral refused to pay a ransom to have it destroyed, the group published 280GB of that data on a dark web leak site.
Have I Been Pwned, the free breach-notification database, analysed the leaked files and confirmed records for 1.6 million accounts — including names, email addresses, phone numbers, and physical addresses.
ShinyHunters is not new to this. The group has been linked to breaches at dozens of Snowflake customers, Salesforce-connected platforms, and recently, organisations hit through an Oracle PeopleSoft zero-day (a previously unknown flaw with no available fix at the time of exploitation). The pattern is consistent: target a third-party integration, steal at scale, demand payment, publish when refused.
RingCentral says the core platform was not disrupted and that affected customers are being contacted directly.
What you should do: Visit Have I Been Pwned and search your email address to find out whether your data appeared in this or any other known breach. If you use RingCentral, watch for phishing emails using your personal details — attackers now know your name, email, and phone number.
Sources

