RingCentral Hit by ShinyHunters Extortion Attack, 1.6M Email Addresses Leaked
Last month, cloud communications provider RingCentral fell victim to an extortion attack by the cybercriminal group ShinyHunters, which later published 1.6 million email addresses and other personal data allegedly stolen from the company.
The leaked data was cross-referenced with existing breaches, revealing that 44% of the exposed email addresses were already present in LinkedIn’s records and other third-party databases. The incident highlights the growing risk of credential reuse and the potential for further exploitation by threat actors.
ShinyHunters, known for targeting high-profile organizations, has previously been linked to breaches involving stolen databases sold or leaked on underground forums. The full scope of the compromised data beyond email addresses remains unclear, but the exposure underscores the persistent threat of extortion-driven cyberattacks in enterprise environments.
The breach was confirmed by security researcher Troy Hunt, who added the exposed emails to the Have I Been Pwned database, allowing users to check for potential exposure. No official statement from RingCentral regarding the attack’s impact or mitigation efforts has been released at this time.
Source: https://www.linkedin.com/feed/update/urn:li:activity:7493622389193211905
RingCentral cybersecurity rating report: https://www.rankiteo.com/company/ringcentral
"id": "RIN1786620488",
"linkid": "ringcentral",
"type": "Breach",
"date": "7/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Cloud Communications',
'name': 'RingCentral',
'type': 'Company'}],
'data_breach': {'data_exfiltration': 'Yes',
'number_of_records_exposed': '1.6 million',
'personally_identifiable_information': 'Yes (email addresses)',
'sensitivity_of_data': 'Moderate (email addresses, potential '
'other personal data)',
'type_of_data_compromised': 'Email addresses, personal data'},
'description': 'Cloud communications provider RingCentral fell victim to an '
'extortion attack by the cybercriminal group ShinyHunters, '
'which later published 1.6 million email addresses and other '
'personal data allegedly stolen from the company. The leaked '
'data was cross-referenced with existing breaches, revealing '
'that 44% of the exposed email addresses were already present '
'in LinkedIn’s records and other third-party databases. The '
'incident highlights the growing risk of credential reuse and '
'the potential for further exploitation by threat actors.',
'impact': {'data_compromised': '1.6 million email addresses and other '
'personal data',
'identity_theft_risk': 'High (due to credential reuse risk)'},
'lessons_learned': 'The incident highlights the growing risk of credential '
'reuse and the potential for further exploitation by '
'threat actors.',
'motivation': 'Extortion',
'ransomware': {'data_exfiltration': 'Yes'},
'references': [{'source': 'Troy Hunt (Have I Been Pwned)'}],
'threat_actor': 'ShinyHunters',
'title': 'RingCentral Hit by ShinyHunters Extortion Attack, 1.6M Email '
'Addresses Leaked',
'type': 'Extortion Attack'}