1.6 million accounts
The extortion group ShinyHunters has claimed responsibility for a data breach at RingCentral, a major provider of cloud communication services, leaking data for approximately 1.6 million customer accounts. The initial intrusion was achieved through a non-technical, social engineering attack known as voice phishing (vishing), where an employee was tricked over the phone into revealing their password. After the company refused to pay a ransom, ShinyHunters published the stolen data, which includes customer names, phone numbers, email addresses, and physical addresses. The incident highlights the effectiveness of social engineering as a primary attack vector against even large technology companies.
On July 28, 2026, ShinyHunters listed RingCentral on its data leak site, issuing a ransom demand and a deadline of July 30. When the company did not comply, the group leaked a data archive of over 623GB on August 3. A spokesperson for the group explicitly stated that the breach was the result of a vishing attack on a single employee, requiring no software exploitation. This tactic underscores the group's focus on human-centric attacks to gain initial access. RingCentral acknowledged the incident, stating a "limited portion" of its customers were affected and that its core services were not compromised. The breach has been verified and added to the Have I Been Pwned database.
The attack vector was purely social engineering, demonstrating that the human element remains a critical vulnerability in enterprise security.
Attack Chain:
T1566.004 - Spearphishing Voice. The attacker impersonated a trusted entity (e.g., IT support) and manipulated the employee into divulging their password.T1078 - Valid Accounts.T1567 - Exfiltration Over Web Service, making the traffic appear legitimate.The leaked data, while not containing financial information or passwords, provides a rich dataset for further criminal activity. The combination of names, emails, phone numbers, and physical addresses is highly valuable for large-scale, targeted phishing, smishing, and vishing campaigns against RingCentral customers. Attackers can leverage the legitimacy of the data to impersonate RingCentral or other service providers, potentially leading to financial fraud or further credential theft. For RingCentral, the breach causes significant reputational damage and erodes customer trust, particularly for a company specializing in secure communications.
No specific Indicators of Compromise (IOCs) such as IP addresses, domains, or file hashes were mentioned in the source articles.
Security teams may want to hunt for the following patterns to detect similar social engineering attempts:
log_sourceHelp Desk Ticket Systemlog_sourceVPN/SSO Logscommand_line_patternAnomalous data queries from non-technical user accountsnetwork_traffic_patternLarge data egress from corporate IP to residential ISPResource Access Pattern Analysis (D3-RAPA).M1017 - User Training.M1032 - Multi-factor Authentication.Outbound Traffic Filtering (D3-OTF).Implement comprehensive and continuous security awareness training focused on identifying and reporting social engineering tactics like vishing.
Deploy phishing-resistant MFA (e.g., FIDO2/WebAuthn) to prevent credential compromise from being a successful initial access vector.
Mapped D3FEND Techniques:
Use User Behavior Analytics (UBA) to detect anomalous activity, such as a user account suddenly accessing and exfiltrating large volumes of customer data.
ShinyHunters lists RingCentral on its leak site with a ransom demand.
The ransom deadline set by ShinyHunters passes.
ShinyHunters leaks the 623GB data archive after non-payment.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.