RingCentral, possibile violazione di dati per 1,6 milioni di persone
Data Breaches

Illustrative image generated with AI

RingCentral: Potential Data Breach Affecting 1.6 Million People

RingCentral, a provider of cloud-based business communications and contact center services, has disclosed an incident that may have affected approximately

Text generated by artificial intelligence, published without human review. AI transparency

Personal Data Stolen in a Social Engineering Attack

RingCentral, a provider of cloud-based business communications and contact center services, has disclosed an incident that may have affected approximately 1.6 million people.

The unauthorized activity allegedly occurred in July and was attributed by the company to a sophisticated social engineering campaign. RingCentral says it identified and blocked the intrusion, then launched an investigation with the support of an independent forensic firm.

The incident was disclosed on August 14, 2026. According to the company, no further unauthorized activity was detected after containment and remediation efforts.

RingCentral also says the incident affected only a limited portion of its customer base. Potentially affected individuals were reportedly contacted directly; according to the company, anyone who did not receive a notification should not be considered part of the incident.

What Information May Have Been Posted Online

The Have I Been Pwned monitoring service added the information contained in the attackers’ published archive to its database on Thursday.

The dataset reportedly contains approximately 1.6 million unique email addresses associated with:

  • names;
  • physical addresses;
  • phone numbers.

However, RingCentral has not confirmed the final number of people affected. It has also not been publicly verified whether the entire archive is authentic or represents all the data that was stolen.

The combination of email addresses, names, phone numbers, and physical addresses increases the risk of targeted attacks. Criminals could use this information to craft convincing messages while impersonating a colleague, supplier, IT manager, or RingCentral itself.

The risk is not limited to email phishing. The same data could support fraudulent phone calls, impersonation attempts, altered payment requests, and new social engineering campaigns targeting the affected organizations.

ShinyHunters’ Claim Remains Unverified

RingCentral has not officially attributed the attack to a specific criminal group. However, ShinyHunters listed the company on its leak site, accessible through the Tor network, at the end of July.

The group claimed to have stolen more than 623 GB of data. About a week later, after allegedly not receiving the requested payment, it reportedly published a 280 GB archive, presenting it as material stolen from RingCentral.

The company has not confirmed these claims. Several aspects of the incident therefore remain unresolved, including the attackers’ identity, the authenticity of all the files, the total volume of data stolen, and whether the published material came from RingCentral’s systems.

The figure of 1.6 million individuals should also be treated as a potential estimate. The dataset contains approximately 1.6 million unique email addresses, but this does not necessarily correspond to the same number of people actually affected.

Core Platform Reportedly Not Compromised

RingCentral provides business telephony, team messaging, video conferencing, and AI-assisted collaboration tools. Its offering also includes contact center and customer interaction features.

According to the company, the incident did not affect the core platform and caused no operational disruptions. Services therefore remain operational while the investigation focuses on the environment from which the data was allegedly stolen.

This distinction does not automatically eliminate the privacy impact. An attack can leave core services operational while exposing enough information to target users, employees, or customers in subsequent campaigns.

No technical vulnerabilities, affected software versions, or CVE identifiers have been disclosed. The incident concerns a compromise attributed to social engineering rather than a publicly classified software flaw. As a result, there is no indication that it is connected to CISA’s KEV Catalog.

Measures Taken by RingCentral

RingCentral says it stopped the unauthorized activity and launched an internal investigation with the assistance of an external forensic firm.

The measures identified by the company include:

  1. blocking the suspicious activity;
  2. investigating the affected environment;
  3. conducting ongoing system monitoring;
  4. verifying that no further unauthorized activity occurred;
  5. directly notifying individuals believed to be affected;
  6. maintaining services without interruption.

It is not known whether further technical details have been released regarding the technique used by the attackers, the systems they accessed, or how the social engineering bypassed the initial controls.

What Users and Organizations Should Do

RingCentral users should review communications received from the company, while verifying the sender through independent channels and avoiding links contained in the messages.

Particular attention should be paid to:

  • emails requesting a password reset;
  • phone calls involving urgent verification requests;
  • messages requesting payments or business information;
  • invitations to install software or provide authentication codes;
  • personalized communications referencing customers, offices, or colleagues.

Potentially exposed credentials should not be reused on other services. If a password was used elsewhere, it should be replaced with a unique, strong credential, and multi-factor authentication should be enabled where available.

Organizations should also alert finance, administration, and customer support teams to the possible fraudulent use of legitimate data. Any request to make a payment, change bank details, or access an account should be verified through a second, previously established channel.

The absence of service disruption does not rule out further fraud attempts. For users who received a notification, the main risk may emerge in upcoming phishing campaigns built around the published data.

Read next

Sources

This article is an original reworking based on the sources below.

Related topicsringcentralpotentialdatabreachaffectingmillionpeople
Back to home