INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

ShinyHunters Extort RingCentral Users with Stolen Data

| 2026-08-14 17:34 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
On August 14, 2026, ShinyHunters, a notorious data theft and extortion gang, successfully executed a sophisticated social engineering campaign against RingCentral, compromising the collaboration platform by voice-phishing an employee who then provided their password. The attackers claimed to have stolen over 623 GB of data from RingCentral, which they threatened to dump online unless the company paid up - a deadline that expired on July 30 without payment being made. As a result, ShinyHunters posted customers' details, including names, physical addresses, and phone numbers, online. This incident is part of hundreds of organizations hacked by this group since the start of the year, affecting sectors such as education tech firms providing services for schools and universities, healthcare-sector organizations, and more.
Technical Mitigations AI-generated
• Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity. • Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc • User Training (ATT&CK mitigation for Social Engineering): Reduces success of phishing/vishing/impersonation and modern “human interface” lures. • Audit (ATT&CK mitigation for Social Engineering): Enables correlation of email/identity/SaaS/endpoint activity that appears legitimate. • Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters
Target & Sectors
NORTH_AMERICA NORTH_AMERICA educationeducation healthhealth
Incident Timeline
‎2026/08/14
ShinyHunters used voice-phishing to trick an employee into giving them the password, allowing them to break into RingCentral's system and dump 1.6 million unique email addresses alongside other sensitive data by July 30 deadline or risk having it leaked online.
threat_actor ShinyHunters
data_breach 20 order records
data_breach 623 GB
Tactical Metrics
Metrics
data_breach
20,000,000
Order Records
Metrics
data_breach
623
Gb
Intelligence Sources
The Register - Cybercrime 2026-08-14