RingCentral Data Breach Exposes Customer Account and Contact Information

Other Commercial data breach illustration
Breach Discovery: July 2026Breach Notification: July 2026

What Happened in the RingCentral Data Breach?

RingCentral, a widely used business communications provider offering cloud calling, messaging, and voicemail services, confirmed that a portion of its customer data was compromised. The company disclosed the incident in a security bulletin published in late July 2026. As a result, affected customers began receiving direct notifications from the company shortly after.

According to the company’s own statement, the breach affected data belonging to a limited portion of RingCentral customers. The threat actor group known as ShinyHunters has claimed responsibility for the intrusion. RingCentral has not publicly detailed the exact method used to gain access, but the company confirmed the incident occurred and that it is working directly with those affected.

Following disclosure, security researchers at ZeroBEC identified a connection worth noting. A phishing-as-a-service platform called Greatness began running a campaign that impersonated RingCentral to target Microsoft 365 users. Because the phishing emails specifically targeted actual RingCentral users, researchers suspect the attackers may have obtained a list of valid targets from the breach, though this link has not been confirmed with certainty.

Investigators are continuing to examine how the stolen RingCentral customer data may have been used elsewhere. This ongoing forensic work highlights a broader risk. Once customer information leaks from one breach, criminals often reuse it to power entirely separate phishing campaigns against unrelated platforms like Microsoft 365.

Who was affected?

RingCentral stated that the breach affected only a limited portion of its customer base. However, the company has not publicly disclosed a specific number of affected individuals or organizations. Because RingCentral serves businesses across many industries, the affected population likely includes employees, administrators, and other authorized users tied to business accounts.

Since RingCentral is a business-to-business communications platform, the exposure may extend beyond direct account holders. For example, employees whose voicemail or messaging data passed through compromised systems could also be affected. The geographic scope has not been publicly detailed, but RingCentral serves customers broadly across the United States.

What Information Was Potentially Exposed?

RingCentral has not released a complete list of every data category compromised in the breach. However, based on the nature of the platform and the subsequent phishing campaign that specifically targeted known RingCentral users, certain types of customer information appear to have been accessed.

  • Customer account identifiers
  • Email addresses associated with RingCentral accounts
  • Information used to identify legitimate RingCentral users for targeting purposes
  • Potentially additional account or contact details tied to affected customers

Even seemingly basic information, such as an email address confirmed to belong to an active RingCentral customer, carries real risk. Attackers can use this kind of validated contact data to craft highly convincing phishing lures. Indeed, that is exactly what happened when the Greatness phishing service began sending fake voicemail and performance-review notifications to real RingCentral users.

Beyond phishing, exposed account data can also enable credential-stuffing attempts, social engineering against IT help desks, and further targeting of an organization’s broader network. Because RingCentral integrates with business communication systems, a compromised account could potentially give attackers a foothold to pursue larger organizational breaches. This means the risk extends beyond any single individual to the businesses they work for.

What is the company doing?

RingCentral has stated that it is communicating directly with affected customers regarding the incident. The company published a security bulletin outlining the situation and has indicated that its investigation into the scope of the breach is ongoing. This direct notification approach allows affected customers to receive specific guidance relevant to their accounts.

In addition to direct outreach, RingCentral appears to be monitoring for further misuse of the compromised data. Security researchers have separately urged organizations that received suspicious RingCentral-branded emails to review their email security configurations. Specifically, they recommend auditing safe-sender lists and requiring valid email authentication rather than relying on blanket domain exclusions.

What Should Affected Individuals Do?

Monitor Your Accounts and Credit Reports

Affected individuals should regularly check their RingCentral account activity for anything unusual. This includes reviewing login history, connected devices, and any changes to account settings that were not made intentionally.

Beyond the RingCentral account itself, it is wise to monitor broader credit reports for signs of identity theft. Because exposed contact information can be combined with other leaked data over time, ongoing vigilance matters even when only limited details were confirmed exposed. Free credit reports can be requested annually from each major credit bureau.

Watch for Phishing Emails Impersonating RingCentral

Given that attackers have already used stolen RingCentral-linked data to impersonate the company in phishing campaigns, affected users should be especially cautious of emails claiming to come from RingCentral. This is particularly true for messages referencing voicemails or performance reviews, since these were used as lures in the observed campaign.

Before clicking any link in such an email, verify the sender’s actual email address rather than trusting the display name alone. As a precaution, log into RingCentral directly through a bookmarked link or official app instead of clicking email links. This simple habit can prevent credential theft even if a phishing email slips past filters.

Enable Multi-Factor Authentication and Review Account Access

Because attackers behind related phishing campaigns specifically targeted Microsoft 365 accounts using adversary-in-the-middle techniques, enabling strong multi-factor authentication is essential. However, it is also important to understand that some MFA methods can be bypassed by sophisticated phishing kits.

For stronger protection, consider using phishing-resistant authentication methods such as hardware security keys where available. In addition, regularly review connected applications and OAuth permissions granted to third-party services. Removing unfamiliar or unused app permissions reduces the chance that a compromised token can be reused later.

Consider Consulting a Data Breach Attorney

If you received a notification from RingCentral about this breach, it may be worth speaking with an attorney who focuses on data breach cases. An attorney can help determine whether you qualify for compensation and explain your legal options clearly.

Many data breach attorneys offer free initial consultations, so there is generally little downside to asking questions. Because deadlines for filing claims can vary depending on the circumstances, acting sooner rather than later is generally the safer approach.



Related Data Breaches

View the full list of tracked data breaches →