Published Security3 min read
RingCentral breach sized at 1.6 million accounts, well past 'a limited portion'
Have I Been Pwned put a number on the ShinyHunters extortion of RingCentral after analysing the leaked archive. The vendor has still not confirmed a count.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- Have I Been Pwned said on Thursday that the leaked RingCentral data it added to its database contained records for 1.6 million accounts, described by SecurityWeek as approximately 1.6 million unique email addresses.
- The exposed data included names, email addresses, phone numbers and physical addresses.
- RingCentral said: "To date, this incident has affected data for a limited portion of RingCentral customers, and we are communicating with affected customers directly."
- RingCentral disclosed the incident on July 28, revealing its systems were compromised following what it described as a "sophisticated social engineering campaign."
- RingCentral said that upon detection it promptly took steps to stop the unauthorized activity and immediately began an investigation with assistance from a leading third-party forensic firm.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Have I Been Pwned added the leaked RingCentral data to its database on Thursday and said it contains records for roughly 1.6 million unique email addresses, along with names, phone numbers and physical addresses [1][2]. That is the first hard figure attached to an incident RingCentral has publicly described only as affecting "a limited portion of RingCentral customers" [3].
The sequence matters more than the framing. RingCentral disclosed the incident on July 28, saying its systems were compromised through what it called a "sophisticated social engineering campaign," that it stopped the unauthorized activity on detection, brought in a third-party forensic firm, and has seen no new unauthorized activity since remediation [4][5][6]. ShinyHunters had already claimed the company on its Tor leak site the day before, on July 27, saying it had taken more than 623GB [7]. Roughly a week later, after RingCentral declined to pay, the group published a 280GB compressed archive [8]. Have I Been Pwned says it confirmed the link to RingCentral after analysing that leaked data [9], and dates the "pay or leak" campaign to July 2026 [10].
Two things follow for anyone running RingCentral for calling, messaging or voicemail. First, the published archive is about 45 percent of the volume ShinyHunters claimed to hold [11], so the 1.6 million figure is a floor derived from what is already circulating, not a ceiling on what was taken. Second, RingCentral's guidance is that "if you are not contacted by RingCentral, you are not affected" [12], and that the core platform was not impacted and services continue to operate [13]. That instruction only works if the vendor's scoping matches the leak set. Have I Been Pwned's count was produced independently of that scoping, from the files themselves [1][9]. If your organisation was not contacted but your users appear in Have I Been Pwned against this incident, the discrepancy is yours to resolve, not the vendor's.
The platform serves more than 600,000 businesses [14]. Spread evenly, 1.6 million accounts is about 2.7 per customer organisation [15], which tells you nothing about distribution but does tell you that "limited portion" and "1.6 million" can both be technically true at the same time. The exposed fields as listed are contact data: names, email addresses, phone numbers, physical addresses [2]. For a voice and messaging vendor, that is a directory of who to call and from what number, which is the raw material for the same social engineering that reportedly started this.
ShinyHunters has a track record of converting one dataset into the next intrusion. The group has claimed breaches at hundreds of Salesforce customers over the past year and says it has stolen more than 1.5 billion records through the Salesloft Drift and Salesforce Aura campaigns [16], has been linked to breaches at more than a dozen Snowflake customers and other third-party integration providers [17], and most recently claimed more than 100 organisations via an Oracle PeopleSoft zero-day [18].
What to watch: whether RingCentral revises its scoping or confirms a number. Both BleepingComputer and SecurityWeek say they contacted the company and had no response at publication [19][20]. Until then, treat tenant contact data as public, re-run your own notification decision rather than waiting for a letter, and expect voice and SMS pretexting against the users in that file.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Have I Been Pwned said on Thursday that the leaked RingCentral data it added to its database contained records for 1.6 million accounts, described by SecurityWeek as approximately 1.6 million unique email addresses.
- [2]
The exposed data included names, email addresses, phone numbers and physical addresses.
- [3]
RingCentral said: "To date, this incident has affected data for a limited portion of RingCentral customers, and we are communicating with affected customers directly."
- [4]
RingCentral disclosed the incident on July 28, revealing its systems were compromised following what it described as a "sophisticated social engineering campaign."
ReportedView cited source - [5]
RingCentral said that upon detection it promptly took steps to stop the unauthorized activity and immediately began an investigation with assistance from a leading third-party forensic firm.
- [6]
RingCentral said it has not seen any new unauthorized activity since taking its remediation efforts.
Sources & coverage · 2 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- securityweek.comIonut ArghireAug 141.6 Million Likely Impacted by RingCentral Data Breach
- bleepingcomputer.comSergiu GatlanAug 14RingCentral data breach exposed info of 1.6 million accounts
Additional citations
- Have I Been Pwned, via BleepingComputer and SecurityWeek
- Have I Been Pwned
- RingCentral notice



