1.6 million RingCentral records leaked, and the entry point was one phone call
ShinyHunters voice-phished a RingCentral employee out of their password in July, took 623GB, and dumped 280GB after the company refused to pay. Have I Been Pwned confirmed 1.6 million accounts including names, emails, phone numbers and addresses.
ShinyHunters breached RingCentral by voice-phishing an employee into handing over their password, claimed the intrusion on July 27, 2026 and said it had taken 623GB. RingCentral disclosed a breach from a social engineering campaign on July 28 and declined to pay. The group published a compressed 280GB archive on its leak site; Have I Been Pwned ingested the data on August 13 and confirmed roughly 1.6 million unique accounts containing names, email addresses, phone numbers and physical addresses. No vulnerability was exploited at any point in the chain, and RingCentral has not reported one.
Why it matters
This is the same operator and the same opening move as the McKesson breach and the EY incident: a phone call, a password, and no exploit anywhere in the chain. Help desk and employee social engineering is now the dominant initial access route for this group, and the reason is arithmetic rather than sophistication. A vishing call costs minutes and works often enough.
The exposed data is the part worth planning around. Names, corporate email addresses and phone numbers for 1.6 million people, sourced from a communications provider, is a target list for the next round of the same attack. Verified phone numbers make the follow-on calls more convincing, which is how these campaigns compound.
A password that can be spoken aloud is the root cause, so the fix is a credential that cannot be: phishing-resistant MFA that produces no code a caller can request. Behind that, a help desk verification procedure that never relies on facts the caller supplies, and step-up authentication on bulk data access so a single session does not export a terabyte quietly.
Sources: BleepingComputer, The Register
Related on Start with Identity
- BlogThe Snowflake attacker pleaded guilty, two years after stale credentials did the work
Connor Riley Moucka pleaded guilty in Seattle federal court on August 6, 2026 to computer fraud, wire fraud, aggravated identity theft, and conspiracy over the
- BlogA Check Point SmartConsole flaw hands out full admin tokens to unauthenticated attackers
CVE-2026-16232 (CVSS 9.3) lets an unauthenticated remote attacker obtain an application login token for Check Point Security Management and Multi-Domain Managem
- BlogA CVSS 10.0 bug let one user's Terraform token serve another user's request
HashiCorp's Terraform MCP Server failed to assign unique session identifiers in stateless HTTP mode, so a token supplied by one user could be reused for later r
- CVECheck Point Security Gateway information disclosure of password hashes
An unauthenticated read on Check Point Security Gateways leaked password hashes, including those used for VPN and local admin. CISA KEV. May 2024. Hash disclosu
- VendorOne Identity
strong_contender
- VendorOne Identity Safeguard
specialist