ShinyHunters Breaches RingCentral, Exposing 1.6 Million Accounts
The notorious **ShinyHunters** extortion group has claimed responsibility for a breach at cloud communications giant **RingCentral**, leading to the theft of personal information from 1.6 million accounts. Despite **RingCentral**'s initial disclosure of a 'sophisticated social engineering campaign,' the company refused to pay a ransom, prompting **ShinyHunters** to leak a substantial trove of data on the dark web.

Cloud-based collaboration and communication platform **RingCentral**, which serves over 600,000 businesses, has fallen victim to a significant data breach orchestrated by the **ShinyHunters** extortion group. The incident, which **RingCentral** initially disclosed on July 28, stemmed from what the company described as a "sophisticated social engineering campaign."
### Extortion and Data Leak
While **RingCentral** did not immediately attribute the breach to a specific actor, **ShinyHunters** publicly claimed responsibility on July 27, asserting they had exfiltrated 623GB of data. Following **RingCentral**'s refusal to meet their ransom demands, **ShinyHunters** proceeded to leak a compressed 280GB archive of files on their dark web leak site.

### **Have I Been Pwned** Confirms Impact
Data breach notification service **Have I Been Pwned** has since confirmed the authenticity of the leaked data after thorough analysis. On Thursday, **Have I Been Pwned** reported that the breach impacted 1.6 million **RingCentral** accounts, with the stolen records containing sensitive information such as names, email addresses, phone numbers, and physical addresses.
**RingCentral** stated, "We have not seen any new unauthorized activity since taking these remediation efforts. To date, this incident has affected data for a limited portion of **RingCentral** customers, and we are communicating with affected customers directly." The company also assured that the core **RingCentral** platform was not impacted and services remain operational.
### **ShinyHunters**' Broader Campaign
The **ShinyHunters** group has a documented history of high-profile data theft and extortion campaigns. In the past year, they have claimed breaches affecting hundreds of **Salesforce** customers, boasting the theft of over 1.5 billion records through campaigns targeting **Salesloft Drift** and **Salesforce Aura**.
Their activities also include attacks on more than a dozen **Snowflake** customers and various other third-party integration providers. More recently, **ShinyHunters** took credit for a new wave of breaches impacting over 100 organizations, exploiting an **Oracle PeopleSoft** zero-day flaw in data-theft operations.