Product1 distinct publisher3 min readUpdated
ShinyHunters says it voice-phished a RingCentral employee. The vendor sells business telephony, and its core platform never broke. The control that failed was a person.
The Product Desk · Product desk

Compiled by The Product DeskSomething wrong?How this is made
ShinyHunters published data taken from RingCentral, and Have I Been Pwned logged 1.6 million leaked records, with The Register reporting the dump on 14 August [1][2]. A spokesperson for the group told The Register's cybersecurity editor, Jessica Lyons, that it got in by voice-phishing a member of staff, with no exploit and no unpatched flaw involved [3][4].
That matters because of what RingCentral sells. It is a cloud communications company whose product is the business telephone [5]. The attack surface here was not a version number. It was somebody picking up a call [4].
The sequence is tight. ShinyHunters listed RingCentral on its leak site on 27 July, claiming more than 623GB of data and setting a 30 July deadline under a banner reading "final warning pay or leak" [6][7]. RingCentral disclosed the intrusion on 28 July in a general advisory on its own trust centre, one day after the listing appeared [8][17]. The company called the incident "a sophisticated social engineering campaign", said it acted to stop the unauthorised activity on detection, brought in a third-party forensic firm, and has seen no new unauthorised activity since [9][10]. It has never named its attacker [11].
The notice is careful about scope, and the carefulness is doing real work. RingCentral said the incident touched data for "a limited portion" of customers, that it is contacting those customers directly, and that customers who have not been contacted are not affected [12]. It also said the core platform was not touched and services continued without disruption [13]. Both statements can be true while 1.6 million records sit on a leak site, because the failure was never in the platform [1][4]. RingCentral did not immediately respond to The Register's request for comment on the dump [14].
Nobody paid. On 3 August, four days after its own deadline, ShinyHunters posted again, complaining that the company had failed to reach an agreement "despite our incredible patience, all the chances and offers we made", and published the data [15][18].
The method is the story, because it repeats. According to security researcher Dominic Alvieri, ShinyHunters is his top threat group and probably most analysts', having hit hundreds of organisations since January [19][20]. It dumped 10.9 million email addresses plus personal and health information from Abbott's cancer diagnostics business, reached the same way, by calling staff and talking them into granting access [21]. Earlier victims include the Moody Bible Institute, where 2.3 million accounts spilled, and Medtronic [22]. At Levi Strauss this month, social engineering reached three computers with no software vulnerability at any point [23]. Across RingCentral, Abbott and Moody alone that is at least 14.8 million individual records taken by telephone [24].
Compare the economics with the group's June campaign, which breached more than 100 organisations through an unpatched Oracle PeopleSoft zero-day rated 9.8 and exploitable over the internet without authentication, hitting some 300 servers and yielding hundreds of thousands of student records including birthdates, enrolment status and grade point averages [25][26]. A zero-day dies when the patch lands. A phone call costs nothing and does not expire [27].
Watch whether RingCentral's "limited portion" figure survives contact with the 1.6 million records now indexed [12][1]. Watch Ernst & Young, listed beside RingCentral on 27 July with a 31 July deadline and the line "Yes it was us", ten days after EY disclosed a separate breach of a third-party support ticket system containing client tax information; nobody has established whether the two are the same incident [28][29][30]. And watch how many vendors respond to this class of failure with a patch cadence slide.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Have I Been Pwned logged the leaked RingCentral records; the headline figure is 1.6 million records.
The Register reported the RingCentral data dump on 14 August.
A ShinyHunters spokesperson told The Register's cybersecurity editor Jessica Lyons that the group broke in by voice-phishing a member of staff.
There was no exploit and no unpatched flaw in the RingCentral intrusion; someone picked up the phone.
ShinyHunters dumped 10.9 million email addresses taken from Abbott's cancer diagnostics business, alongside personal and health information, reaching the company by calling staff and talking them into granting access.
Earlier ShinyHunters victims include the Moody Bible Institute, where 2.3 million accounts spilled, and the pacemaker maker Medtronic.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Named primary anchors, single covering publisher
Claims trace to identifiable primary artefacts — RingCentral's own trust-centre advisory, the leak-site listings, Have I Been Pwned's logged count, The Register's reporting by its named cybersecurity editor, and named researchers Dominic Alvieri and Dark Web Intelligence. But the cluster contains exactly one publisher restating that chain, the intrusion method rests on the attacker's own spokesperson, and the central scope figure is unreconciled with the vendor's statement, which caps the evidentiary weight well short of corroborated.
Dated incident sequence plus repeated victim pattern
This is a real, dated and completed event chain rather than an announcement: listing, vendor advisory, expired deadline, publication of data, and ingestion into a public breach index. The same technique is documented against several further named organisations in the same period, and a parallel zero-day campaign against more than 100 organisations, which establishes the method as widely realised in practice rather than theoretical.
Headline number outruns the confirmed scope
The framing — 1.6 million records lost to a phone call — leans on a count logged by a third-party index and an entry method asserted by the extortion group, neither confirmed by the victim, whose own statement describes a limited portion of customers and an untouched core platform. The 623GB claim comes from the attacker's ransom listing. The article is honest about the gap and names reconciliation as an open question, which keeps the overstatement modest rather than severe.
Both primary voices have strong reasons to shade the numbers
The volume, victim count and method all originate with an extortion crew whose business depends on appearing capable and on maximising pressure to pay, and which published only after payment was refused. The counter-narrative comes from the breached vendor, which has an interest in minimising perceived scope, protecting its core-platform claim and declining to name an attacker. The covering publisher's framing turns on the irony that a telephony vendor fell to a telephone call, which favours the sharper reading.
Event chain solid, magnitude and attribution soft
That an intrusion occurred, was disclosed on 28 July, went unpaid and ended in publication indexed by Have I Been Pwned is well supported by named artefacts and consistent dating. What remains uncertain is the true affected population, whether the 1.6 million logged addresses reconcile with the vendor's limited-portion statement, and whether the EY listing is a new incident. With one publisher covering all of this, confidence sits just above the midpoint.
product
The AI-wrote-it claim died in eight hours. The Actions injection pattern did not.1 distinct publisher
leadership
The extortion call now comes from your help desk, and the fix is a procedure you own1 distinct publisher
product
Cinemas, classrooms and ICE: smart glasses now need a venue-policy contingency1 distinct publisher
product
OpenAI prices its own guardrails: 20% more compute, plus a two-week training pause1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 15, 2026