RingCentral data breach exposes 1.6M accounts after ShinyHunters extortion leak

RingCentral data breach exposes 1.6M accounts after ShinyHunters extortion leak

The notorious hacking group ShinyHunters has publicly released a database containing information on 1.6 million user accounts from RingCentral, a cloud-based video conferencing and communications platform. The leak follows a failed extortion attempt: the attackers demanded a ransom from the company and, when their demands were not met, published the stolen data online.

According to security researchers, the compromised archive includes user names, email addresses, phone numbers, and other personal details. Some of the data, including password hashes, could be leveraged for further malicious activities, such as phishing campaigns or credential-stuffing attacks against users who reuse passwords across multiple services.

RingCentral has confirmed the incident and launched an investigation. The company said it is notifying affected customers and implementing measures to secure their accounts. Security experts urge users whose data may have been exposed to change their passwords immediately, particularly if they used the same credentials elsewhere.

ShinyHunters is well known for a string of high-profile breaches and database dumps, having previously targeted companies like AT&T and Ticketmaster. Analysts note that data leaks of this scale are becoming increasingly common, and extortion remains one of the most significant threats to businesses that store large volumes of user information. The incident underscores the growing pressure on organizations to strengthen their security posture and respond swiftly to data theft attempts.

Tags: Security
Slate (Sl8) — the new social network. Post, grow your audience and earn — plus staking rewards that actually pay.
Invite codehXA6hX
Join Slate