INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
ShinyHunters Extort RingCentral Users with Stolen Data
| 2026-08-14 17:34 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
On August 14, 2026, ShinyHunters, a notorious data theft and extortion gang, successfully executed a sophisticated social engineering campaign against RingCentral, compromising the collaboration platform by voice-phishing an employee who then provided their password. The attackers claimed to have stolen over 623 GB of data from RingCentral, which they threatened to dump online unless the company paid up - a deadline that expired on July 30 without payment being made. As a result, ShinyHunters posted customers' details, including names, physical addresses, and phone numbers, online. This incident is part of hundreds of organizations hacked by this group since the start of the year, affecting sectors such as education tech firms providing services for schools and universities, healthcare-sector organizations, and more.
Technical Mitigations AI-generated
• Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity.
• Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc
• User Training (ATT&CK mitigation for Social Engineering): Reduces success of phishing/vishing/impersonation and modern “human interface” lures.
• Audit (ATT&CK mitigation for Social Engineering): Enables correlation of email/identity/SaaS/endpoint activity that appears legitimate.
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
educationeducation
healthhealth
Incident Timeline
2026/08/14
ShinyHunters used voice-phishing to trick an employee into giving them the password, allowing them to break into RingCentral's system and dump 1.6 million unique email addresses alongside other sensitive data by July 30 deadline or risk having it leaked online.
Click on any entity below to view its context and source!
threat_actor
ShinyHunters
A ShinyHunters spokesperson told us that the group broke into RingCentral by voice-phishing an employee and tricking them into giving the crooks their password.
Recently, ShinyHunters dumped data
stolen from Abbott’s cancer diagnostics business
with the leak containing 10.9 million unique email addresses alongside personal and health information.
1.6M RingCentral accounts' data dumped after ShinyHunters extortion attack.
CYBER-CRIME
1.6M RingCentral accounts' data dumped after ShinyHunters extortion attack
Another one bites the dust
Some 1.6 million unique email addresses tied to RingCentral have been leaked online, alongside names, physical addresses, an…
While the company hasn’t named its attacker, notorious data theft and extortion gang ShinyHunters previously claimed it compromised the collaboration platform, according to a post on its data leak site, viewed by
The Register.
RingCentral apparently didn’t pay the extortion demand, and ShinyHunters followed through on its threat, posting customers’ details on the internet.
®
Editor's note: This story was amended post-publication with comment from ShinyHunters.
data_breach
20 order records
More concerning, however, they said the haul includes 22 million-plus rows of client notes containing confidential doctor-patient conversations and health information, and more than 20 million medical-order records containing patient IDs, prescripti…
data_breach
623 GB
The crooks claimed they stole more than 623 GB of data, and set a July 30 deadline for RingCentral to pay up - or else the crew would dump the stolen information online.
Tactical Metrics
Metrics
data_breach
20,000,000
Order Records
Click for context!
More concerning, however, they said the haul includes 22 million-plus rows of client notes containing confidential doctor-patient conversations and health information, and more than 20 million medical-order records containing patient IDs, prescripti…
Metrics
data_breach
623
Gb
The crooks claimed they stole more than 623 GB of data, and set a July 30 deadline for RingCentral to pay up - or else the crew would dump the stolen information online.
Intelligence Sources
The Register - Cybercrime
2026-08-14
1.6M RingCentral accounts' data dumped after ShinyHunters extortion attack
The Register - Cybercrime
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-06T12:16
Comprehensive Tactical Telemetry
Highly Correlated Entities
4x
tactic
Cyber Operation Type
Phishing
tactic
4x
industry
Targeted Sector
Media
sector
4x
organisation
Identified Entity
RingCentral
entity
3x
timeline
Temporal Reference
July 28
date
2x
general metric
Rows
22,000,000
rows
Contextual Telemetry
Context Block
7 METRICS
target region
Target Country
United States
country
source region
Origin Country
United States
country
threat actor
APT Group
ShinyHunters
actor
data breach
Order Records
20,000,000
order records
general metric
Ringcentral Accounts
1,600,000
ringcentral accounts
data breach
Gb
623
gb
general metric
Dates
7,500,000
dates
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.