Product1 publisher3 min readPublished
RingCentral lost 1.6 million records to a phone call, not a missing patch
ShinyHunters says it voice-phished a RingCentral employee. The vendor sells business telephony, and its core platform never broke. The control that failed was a person.
The Product Desk · Product desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Have I Been Pwned logged the leaked RingCentral records; the headline figure is 1.6 million records.
- The Register reported the RingCentral data dump on 14 August.
- A ShinyHunters spokesperson told The Register's cybersecurity editor Jessica Lyons that the group broke in by voice-phishing a member of staff.
- There was no exploit and no unpatched flaw in the RingCentral intrusion; someone picked up the phone.
- RingCentral is a cloud communications company and its product is the business telephone.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
ShinyHunters published data taken from RingCentral, and Have I Been Pwned logged 1.6 million leaked records, with The Register reporting the dump on 14 August [1][2]. A spokesperson for the group told The Register's cybersecurity editor, Jessica Lyons, that it got in by voice-phishing a member of staff, with no exploit and no unpatched flaw involved [3][4].
That matters because of what RingCentral sells. It is a cloud communications company whose product is the business telephone [5]. The attack surface here was not a version number. It was somebody picking up a call [4].
The sequence is tight. ShinyHunters listed RingCentral on its leak site on 27 July, claiming more than 623GB of data and setting a 30 July deadline under a banner reading "final warning pay or leak" [6][7]. RingCentral disclosed the intrusion on 28 July in a general advisory on its own trust centre, one day after the listing appeared [8][17]. The company called the incident "a sophisticated social engineering campaign", said it acted to stop the unauthorised activity on detection, brought in a third-party forensic firm, and has seen no new unauthorised activity since [9][10]. It has never named its attacker [11].
The notice is careful about scope, and the carefulness is doing real work. RingCentral said the incident touched data for "a limited portion" of customers, that it is contacting those customers directly, and that customers who have not been contacted are not affected [12]. It also said the core platform was not touched and services continued without disruption [13]. Both statements can be true while 1.6 million records sit on a leak site, because the failure was never in the platform [1][4]. RingCentral did not immediately respond to The Register's request for comment on the dump [14].
Nobody paid. On 3 August, four days after its own deadline, ShinyHunters posted again, complaining that the company had failed to reach an agreement "despite our incredible patience, all the chances and offers we made", and published the data [15][18].
The method is the story, because it repeats. According to security researcher Dominic Alvieri, ShinyHunters is his top threat group and probably most analysts', having hit hundreds of organisations since January [19][20]. It dumped 10.9 million email addresses plus personal and health information from Abbott's cancer diagnostics business, reached the same way, by calling staff and talking them into granting access [21]. Earlier victims include the Moody Bible Institute, where 2.3 million accounts spilled, and Medtronic [22]. At Levi Strauss this month, social engineering reached three computers with no software vulnerability at any point [23]. Across RingCentral, Abbott and Moody alone that is at least 14.8 million individual records taken by telephone [24].
Compare the economics with the group's June campaign, which breached more than 100 organisations through an unpatched Oracle PeopleSoft zero-day rated 9.8 and exploitable over the internet without authentication, hitting some 300 servers and yielding hundreds of thousands of student records including birthdates, enrolment status and grade point averages [25][26]. A zero-day dies when the patch lands. A phone call costs nothing and does not expire [27].
Watch whether RingCentral's "limited portion" figure survives contact with the 1.6 million records now indexed [12][1]. Watch Ernst & Young, listed beside RingCentral on 27 July with a 31 July deadline and the line "Yes it was us", ten days after EY disclosed a separate breach of a third-party support ticket system containing client tax information; nobody has established whether the two are the same incident [28][29][30]. And watch how many vendors respond to this class of failure with a patch cadence slide.