// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE BRC-hibpDTG 0600Z
ColdRecon / Breach Radar / RingCentral
Breach Record

RingCentral

DISCLOSED 2026-07-27 · STOLEN CREDS · 1,596,490 RECORDS EXPOSED

In July 2026, the cloud-based business communications platform RingCentral was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data they claimed was obtained from the platform, which included 1.6M unique email addresses along with names, physical addresses and phone numbers. In their disclosure notice, RingCentral advised that...

The record

What we know

Disclosed
2026-07-27
Attack vector
Stolen Creds
Records exposed
1,596,490
Domain
ringcentral.com
Data classes exposed
Email addressesNamesPhone numbersPhysical addresses
Sources

Cited reporting

Similar vector · recent

Other stolen creds breaches on file

This page is the permanent ColdRecon entry for the RingCentral disclosure. It updates if new public reporting emerges. All tracked breaches →

RingCentral just lived through this. Your next prospect doesn't have to.

ColdRecon turns every disclosed breach into a daily intelligence brief from the seller's seat — normalized to the factors that move a deal, written in the Handler's voice. Request clearance and the first lands tomorrow at 0600.

Request Clearance →