Threat Intelligence Brief
Curated summary with source attribution
Source: haveibeenpwned.com
Threat Risk: Medium
Victim: RingCentral customers
Incident: A data breach involving the extortion and leak of customer information.
Impact: Exposure of PII for 1.6 million users, increasing vulnerability to phishing.
Attacker: ShinyHunters
Analysis: The ShinyHunters group targeted RingCentral in a ‘pay or leak’ scheme, eventually releasing data for 1.6 million users. The leaked information includes sensitive PII such as phone numbers and physical addresses, which significantly increases the risk of targeted phishing and social engineering attacks.
Recommendations: Implement multi-factor authentication (MFA) across all corporate accounts.; Alert employees to be vigilant against highly targeted social engineering attempts.; Rotate credentials for any accounts potentially linked to the leaked email addresses.
Source: Have I Been Pwned
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source
Latest Developments
Update — 2026-08-15 09:07 UTC
Leak of 1.6 million user account records following an extortion attempt. Massive exposure of sensitive user data and increased vulnerability to secondary attacks. The threat actor ShinyHunters has leaked a dataset containing 1.6 million RingCentral accounts. This event follows a pattern of targeted extortion against cloud-based service providers. The availability of this data significantly increases the risk of credential stuffing and social engineering attacks against affected users.
Corroborating source: theregister.com