Phone Company Loses 1.6 Million Records to Phone Call
ShinyHunters has dumped 1.6 million email addresses belonging to RingCentral customers, along with names, home addresses, and phone numbers. The group claims they gained access by ringing an employee and convincing them to disclose their password.
August 15, 2026 – 12:28 pm
Credit: Canva
The leaked records have been logged on Have I Been Pwned, and The Register reported the dump on August 14th. Jessica Lyons, its cybersecurity editor, spoke with a ShinyHunters spokesperson who revealed the group achieved access through voice-phishing a RingCentral staff member.
There was no exploit or unpatched flaw involved; instead, a simple phone call was enough to gain unauthorized access.
The Details of the Incident
What makes this case particularly notable is the nature of the data RingCentral handles. RingCentral is a cloud communications company specializing in business telephone services.
RingCentral’s Response
RingCentral disclosed the intrusion on July 28th in a general advisory notice on its trust center. They described the attack as "a sophisticated social engineering campaign" and stated they took immediate action upon detecting the unauthorized activity. They also engaged a leading third-party forensic firm and have seen no further unauthorized activity since.
The timing is interesting. ShinyHunters initially listed RingCentral on July 27th, and the advisory was dated the following day. RingCentral has not publicly named their attacker.
The notice specifies that the incident affected only a "limited portion" of customers, and the company is directly contacting those affected. If you haven’t heard from RingCentral, you are not impacted.
They also emphasized that the incident did not compromise the core platform and services continued without disruption.
The Countdown and Leaked Data
ShinyHunters listed RingCentral on its leak site on July 27th, claiming over 623GB of data and setting a deadline of July 30th. They also included a final warning, encouraging companies to make the "right decision" and avoid becoming the next headline.
The deadline passed, and no payment was made. On August 3rd, ShinyHunters published the data.
A Big Four Firm Also Affected
On the same day, ShinyHunters also listed Ernst & Young (EY) with a deadline of July 31st. They promised to release all data and files after the deadline, indicating a potential separate incident or a second instance involving EY.
EY had previously disclosed a breach in March-April, affecting a third-party support ticket system with client tax information.
A Pattern of Attacks
This is not an isolated incident. ShinyHunters has been targeting hundreds of organizations since January, making it a top threat group according to security researcher Dominic Alvieri.