// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE BRC-newsDTG 0600Z
ColdRecon / Breach Radar / RingCentral
Breach Record

RingCentral

DISCLOSED 2026-08-16 · PHISHING · 1,600,000 RECORDS EXPOSED

RingCentral, a business phone systems provider, was breached by the extortion group ShinyHunters. The attackers used voice phishing to compromise a single staff member. The breach exposed 1.6 million customer records.

The record

What we know

Disclosed
2026-08-16
Attack vector
Phishing
Sector
Technology
Country
US
Records exposed
1,600,000
Domain
ringcentral.com
Data classes exposed
customer records
ENDPOINT INVOLVED
ColdRecon assessment

Could a positive-security control have prevented this?

Verdict · unclear · opinion

A positive-security model might have prevented unauthorized access if the phished employee's endpoint was restricted, but the text does not specify how the breach occurred after the phishing call.

Our assessments are opinion, grounded in the cited public facts. Read them critically.

Sources

Cited reporting

Similar vector · recent

Other phishing breaches on file

This page is the permanent ColdRecon entry for the RingCentral disclosure. It updates if new public reporting emerges. All tracked breaches →

RingCentral just lived through this. Your next prospect doesn't have to.

ColdRecon turns every disclosed breach into a daily intelligence brief from the seller's seat — normalized to the factors that move a deal, written in the Handler's voice. Request clearance and the first lands tomorrow at 0600.

Request Clearance →