INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
RingCentral Exposes 1.6 Million Accounts
| 2026-08-14 10:52 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
On July 28, 2026, RingCentral disclosed a data breach that exposed information from 1.6 million of its accounts following a "sophisticated social engineering campaign". The ShinyHunters extortion group is believed to be behind the incident, although RingCentral has not attributed it to a specific threat actor or hacking group. This attack affected a limited portion of RingCentral customers and did not impact the core platform, with services continuing to operate without disruption. After refusing to pay a ransom, ShinyHunters leaked 280GB worth of files containing records for 1.6 million accounts on their dark web leak site, confirming that the data breach had indeed exposed information from this number of accounts.
Technical Mitigations AI-generated
• Patch Oracle PeopleSoft zero-day flaw to prevent exploitation
• Use a robust security framework with multi-factor authentication and access controls
• Monitor for suspicious activity on third-party integration providers, such as Snowflake
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters
Target & Sectors
Global Scope
Incident Timeline
July 2026
ShinyHunters claimed responsibility for a new series of data-theft attacks that exploited an Oracle PeopleSoft zero-day flaw, targeting over 100 organizations.
Click on any entity below to view its context and source!
threat_actor
ShinyHunters
Most recently, ShinyHunters claimed responsibility for a new series of breaches at
over 100 organizations
following data-theft attacks
that exploited an Oracle PeopleSoft zero-day flaw
.
victims
100 organizations
Most recently, ShinyHunters claimed responsibility for a new series of breaches at
over 100 organizations
following data-theft attacks
that exploited an Oracle PeopleSoft zero-day flaw
.
2026/08/14
Threat actors, claiming to be ShinyHunters, leaked a compressed archive containing 280GB worth of stolen data from RingCentral's systems after the company refused to pay a ransom.
Click on any entity below to view its context and source!
threat_actor
ShinyHunters
The ShinyHunters extortion group stole personal information from 1.6 million RingCentral accounts after hacking the company in July, according to the data breach notification service Have I Been Pwned.
…RingCentral has not attributed the breach to a specific threat actor or hacking group and has yet to share further details on the incident, the ShinyHunters extortion gang
claimed responsibility
on July 27, claiming they had stolen 623GB of data.
"In July 2026, the cloud-based business communications platform RingCentral was the target of a ShinyHunters 'pay or leak' extortion campaign," it said.
RingCentral entry on ShinyHunters' data leak site (BleepingComputer)
After the company refused to pay a ransom to have the stolen data destroyed, the cybercrime group leaked a compressed archive containing 280GB worth of files on their dark web…
While a RingCentral spokesperson didn't immediately reply when contacted by BleepingComputer to confirm ShinyHunters' claims, Have I Been Pwned confirmed the link after analyzing the leaked data and said on Thursday that it
contained records for 1…
Although RingCentral has yet to share exactly how the threat actors gained access to its systems, ShinyHunters has claimed breaches at
hundreds of Salesforce customers
over the past year, saying they've stolen over 1.5 billion records in
Saleslo…
data_breach
623 GB
Although RingCentral has not attributed the breach to a specific threat actor or hacking group and has yet to share further details on the incident, the ShinyHunters extortion gang
claimed responsibility
on July 27, claiming they had stolen 623GB…
data_breach
280 GB
RingCentral entry on ShinyHunters' data leak site (BleepingComputer)
After the company refused to pay a ransom to have the stolen data destroyed, the cybercrime group leaked a compressed archive containing 280GB worth of files on their dark web l…
data_breach
1.5 records
Although RingCentral has yet to share exactly how the threat actors gained access to its systems, ShinyHunters has claimed breaches at
hundreds of Salesforce customers
over the past year, saying they've stolen over 1.5 billion records in
Saleslof…
Tactical Metrics
Metrics
data_breach
623
Gb
Click for context!
Although RingCentral has not attributed the breach to a specific threat actor or hacking group and has yet to share further details on the incident, the ShinyHunters extortion gang
claimed responsibility
on July 27, claiming they had stolen 623GB…
Metrics
data_breach
280
Gb
RingCentral entry on ShinyHunters' data leak site (BleepingComputer)
After the company refused to pay a ransom to have the stolen data destroyed, the cybercrime group leaked a compressed archive containing 280GB worth of files on their dark web l…
Metrics
data_breach
1,500,000,000
Records
Although RingCentral has yet to share exactly how the threat actors gained access to its systems, ShinyHunters has claimed breaches at
hundreds of Salesforce customers
over the past year, saying they've stolen over 1.5 billion records in
Saleslof…
Metrics
victims
100
Organizations
Most recently, ShinyHunters claimed responsibility for a new series of breaches at
over 100 organizations
following data-theft attacks
that exploited an Oracle PeopleSoft zero-day flaw
.
Intelligence Sources
BleepingComputer
2026-08-14
RingCentral data breach exposed info of 1.6 million accounts
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-06T12:17
Comprehensive Tactical Telemetry
Highly Correlated Entities
4x
tactic
Cyber Operation Type
Data Breach
tactic
4x
organisation
Identified Entity
RingCentral
entity
3x
timeline
Temporal Reference
July 28
date
2x
data breach
Gb
623
gb
Contextual Telemetry
Context Block
7 METRICS
general metric
Accounts
1,600,000
accounts
threat actor
APT Group
ShinyHunters
actor
data breach
Records
1,500,000,000
records
victims
Organizations
100
organizations
general metric
Blue Report
2,026
blue report
general metric
Simulations
338,000,000
simulations
general metric
Businesses
600,000
businesses
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.