INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

RingCentral Exposes 1.6 Million Accounts

| 2026-08-14 10:52 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
On July 28, 2026, RingCentral disclosed a data breach that exposed information from 1.6 million of its accounts following a "sophisticated social engineering campaign". The ShinyHunters extortion group is believed to be behind the incident, although RingCentral has not attributed it to a specific threat actor or hacking group. This attack affected a limited portion of RingCentral customers and did not impact the core platform, with services continuing to operate without disruption. After refusing to pay a ransom, ShinyHunters leaked 280GB worth of files containing records for 1.6 million accounts on their dark web leak site, confirming that the data breach had indeed exposed information from this number of accounts.
Technical Mitigations AI-generated
• Patch Oracle PeopleSoft zero-day flaw to prevent exploitation • Use a robust security framework with multi-factor authentication and access controls • Monitor for suspicious activity on third-party integration providers, such as Snowflake
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters
Target & Sectors
Global Scope
Incident Timeline
‎July 2026
ShinyHunters claimed responsibility for a new series of data-theft attacks that exploited an Oracle PeopleSoft zero-day flaw, targeting over 100 organizations.
threat_actor ShinyHunters
victims 100 organizations
‎2026/08/14
Threat actors, claiming to be ShinyHunters, leaked a compressed archive containing 280GB worth of stolen data from RingCentral's systems after the company refused to pay a ransom.
threat_actor ShinyHunters
data_breach 623 GB
data_breach 280 GB
data_breach 1.5 records
Tactical Metrics
Metrics
data_breach
623
Gb
Metrics
data_breach
280
Gb
Metrics
data_breach
1,500,000,000
Records
Metrics
victims
100
Organizations
Intelligence Sources
BleepingComputer 2026-08-14