
Work Here?
Work Here?
Work Here?
RingCentral provides cloud-based communication and collaboration tools for businesses. It offers a unified RingCentral App that combines voice, video, messaging, and collaboration so users can manage calls, messages, and meetings across any device. Additional services include RingCentral Fax and RingCentral Contact Center, all delivered through a subscription model. Revenue comes from recurring subscription fees and an affiliate program that rewards partners for selling the services. The company differentiates itself with an integrated, global cloud communications suite and strategic partnerships (for example with AT&T) that extend reach. Its goal is to simplify and unify business communications and collaboration on a global scale.
Industries
Consumer Software
Enterprise Software
Company Size
5,001-10,000
Company Stage
IPO
Headquarters
Belmont, California
Founded
2003
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Total Funding
$543.4M
Above
Industry Average
Funded Over
7 Rounds
Health Insurance
Dental Insurance
Vision Insurance
Life Insurance
Disability Insurance
Health Savings Account/Flexible Spending Account
Unlimited Paid Time Off
Paid Vacation
Paid Sick Leave
Paid Holidays
Hybrid Work Options
401(k) Retirement Plan
401(k) Company Match
Family Planning Benefits
Fertility Treatment Support
Employee Assistance Program (EAP)
Professional Development Budget
Wellness Program
RingCentral data breach: 1.6 million accounts reportedly exposed. RingCentral is facing scrutiny after a social engineering attack reportedly exposed personal information connected to approximately 1.6 million accounts. The cloud-based business communications provider confirmed that it was targeted in what it described as a sophisticated social engineering campaign. While RingCentral says its core platform was not affected, subsequent reporting indicates that names, email addresses, phone numbers, and physical addresses may have been accessed and published online. For businesses, the incident raises important questions about how customer information is protected, how quickly affected organizations are notified, and how a breach involving a major technology provider can create risks beyond the provider's own network. What RingCentral has confirmed. RingCentral published a general security advisory on July 28, 2026. The company said it had recently discovered that it was the target of a sophisticated social engineering campaign. According to RingCentral, it stopped the unauthorized activity and began an investigation with help from a third-party forensic firm. The company said it had not observed additional unauthorized activity after taking corrective action. RingCentral described the impact as limited to data associated with a portion of its customers and said it was contacting those customers directly. Its core platform was not affected, and services continued without disruption. Where the 1.6 million figure comes from. On August 13, 2026, breach notification service Have I Been Pwned added the incident to its database after reviewing information published by the attackers. It identified approximately 1.6 million unique email addresses in the dataset. The exposed information reportedly also included names, physical addresses, and phone numbers. As of August 15, RingCentral had not publicly confirmed that 1.6 million people were affected. It had also not verified the full volume of data allegedly stolen. The number should therefore be understood as an estimate based on independent analysis of the published information, not a final count announced by RingCentral. Public reporting has attributed the incident to the ShinyHunters extortion group, which claimed it stole more than 623 gigabytes of data. RingCentral has not publicly attributed the attack to ShinyHunters or confirmed that figure. The attackers also reportedly claimed that they gained access by voice-phishing an employee and convincing that person to reveal a password. RingCentral has confirmed that social engineering was involved, but it has not publicly confirmed the specific method used. What information was reportedly exposed? Have I Been Pwned identified the following information in the published dataset: * Names * Email addresses * Phone numbers * Physical addresses Its public entry does not list passwords, Social Security numbers, or financial information among the exposed categories. That does not necessarily provide a complete picture of every file involved. Even without those details, this combination of contact information can help criminals create convincing emails, text messages, and phone calls. Why follow-up scams are a concern. After a widely reported breach, criminals often take advantage of the confusion. Employees may receive messages or calls claiming to come from RingCentral, an IT provider, or an internal administrator. They may be asked to reset a password, review a voicemail, install an update, or provide a multifactor authentication code. Because the attacker may already possess accurate personal details, the request can appear legitimate. Leaked information may be reused in phishing, voice phishing, business email compromise, and account takeover attempts. What RingCentral customers should do. RingCentral says it is notifying affected customers directly. Businesses should review any notice carefully, but employees should avoid clicking links or calling numbers in unexpected messages. Organizations should also consider the following precautions: * Warn employees about breach-related phishing and phone scams. * Require strong, unique passwords and multifactor authentication for communications and administrator accounts. * Never approve an unexpected authentication request or give a one-time code to a caller. * Review administrator access, recent activity, integrations, forwarding settings, and unexpected configuration changes. * Report suspicious messages or calls to the IT or security team before responding. Individuals can also use Have I Been Pwned to check whether an email address appears in the published dataset. A match means the address was found in the data reviewed by the service, but it does not replace direct communication from RingCentral or a formal investigation. What this breach means for other businesses. The RingCentral incident is a reminder that cybersecurity is not limited to firewalls, antivirus software, and software patches. Social engineering targets people and the business processes they trust. One convincing phone call may be enough to bypass otherwise strong technical safeguards. It also shows why businesses must pay attention to third-party risk. Technology vendors may hold information that becomes useful to attackers, even when their primary services remain available. The goal is not to panic every time a major provider reports an incident. The goal is to be prepared. Businesses should know which vendors store sensitive information, who receives security notices, and how the organization will respond. Employee awareness training, multifactor authentication, limited administrator access, and a documented incident response plan can all help prevent one breach from leading to another. Incidents like this are also a good reminder to consider who manages your business communications and what kind of support is available when questions arise. If your business is exploring other options, TotalBC's CallNet VoIP provides a locally supported alternative backed by a team you can reach when you need help. Contact TotalBC to learn more about making the switch.
RingCentral data breach hits 1.6 million users. Cloud communications provider RingCentral is investigating a July 2026 data breach after an extortion group published a trove of customer data linked to roughly 1.6 million accounts, including names, email addresses, phone numbers, and physical addresses.[[1]] [[3]] [[10]] The incident stems from a "pay or leak" campaign attributed to the ShinyHunters cybercrime group, which listed RingCentral on its leak site in late July and threatened to release stolen files if a ransom demand was not met.[[5]] [[9]] [[15]] Subsequent reports from breach-tracking services and security outlets say the group ultimately dumped a large compressed archive of internal data on its leak site after RingCentral declined to pay.[[3]] [[10]] RingCentral publicly acknowledged a security incident on July 28, describing a compromise following what it called a sophisticated social engineering campaign against its systems.[[3]] [[6]] The company has said that the breach affected data for a limited portion of its customers, that no new unauthorized activity has been observed since remediation steps were taken, and that the core RingCentral platform continues to operate without disruption.[[2]] [[3]] [[6]] Customers have been told they will be contacted directly if their data was involved and that those not notified are not considered affected.[[2]] [[3]] Independent breach monitors now estimate that the exposed dataset contains about 1.6 million unique email addresses tied to RingCentral accounts, accompanied by associated contact details.[[1]] [[7]] [[8]] One breach-aggregation site further lists Social Security numbers among the data types linked to the incident, though this specific claim has not been prominently echoed in other public reporting and may reflect only a subset of records.[[11]] Have I Been Pwned's analysis indicates that roughly 44 percent of the email addresses in the dump were already present in its database from earlier breaches, underscoring how repeated compromises can amplify identity and fraud risks.[[1]] [[10]] Computer Security While full technical details of the intrusion have not been disclosed, current reporting emphasizes social engineering rather than an exploit of a specific software vulnerability.[[3]] [[6]] The campaign aligns with ShinyHunters' broader playbook of data theft followed by extortion, in which attackers seek payment in exchange for withholding or deleting stolen information, then move to leak sites when targets refuse.[[5]] [[9]] [[15]] The publication of contact data at this scale significantly increases the likelihood of targeted phishing, business email compromise, and account takeover attempts against RingCentral customers and employees.[[7]] [[8]] Organizations that rely on RingCentral are being urged by breach trackers and industry observers to step up phishing awareness, enable multifactor authentication on all accessible accounts, and review email filtering and identity verification processes to catch suspicious login attempts and communications.[[7]] [[8]] [[10]] Affected individuals and companies should monitor for unusual activity tied to exposed email addresses and phone numbers, treat unsolicited messages referencing RingCentral as high-risk, and consider credential resets wherever the same passwords may have been reused across services.[[1]] [[10]]
Critical alert: recent ringcentral data breach. HookPhish team Introduction. The latest breach involves RingCentral with a domain of ringcentral.com. This breach occurred on 2026-07-27. Overview. In July 2026, the cloud-based business communications platform RingCentral was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data they claimed was obtained from the platform, which included 1.6M unique email addresses along with names, physical addresses and phone numbers. In their disclosure notice, RingCentral advised that the incident affected "a limited portion of RingCentral customers" and that it was communicating directly with those affected. the breach of RingCentral poses serious risks, including potential phishing attacks, identity theft, and other security concerns. Breach details. * Breach Name: RingCentral * Breach Date: 2026-07-27 * Compromised Accounts: 1,596,490 * Compromised Data: Email addresses, Names, Phone numbers, Physical addresses Disclaimer. HookPhish does not host, download, or disclose any breached data. This post is editorial cybersecurity news intended to raise awareness of organisations affected by data breaches. Breach details are sourced from publicly available threat-intelligence feeds (Have I Been Pwned) for awareness purposes only. How to protect yourself after a data breach. Breached credentials often resurface in phishing and account-takeover attacks. A few steps sharply cut your exposure: * awareness training - stay ahead of attackers reusing leaked data. * phishing simulations - stay ahead of attackers reusing leaked data. Check whether your organisation's data is already exposed with the free HookPhish data breach checker. Faq. What should I do if I was affected by this breach? Changing your passwords immediately is a crucial first step. Consider using unique, strong passwords for each of your accounts. How can I check if my email address was part of the compromised data? You can use online tools or services that allow you to check if your email address has been involved in recent data breaches. Be cautious about inputting sensitive information into unknown websites and prefer reputable platforms. Is two-factor authentication (2FA) recommended after this incident? Yes, enabling 2FA adds an extra layer of security to your accounts. It's highly recommended to activate 2FA wherever possible to enhance the protection of your online accounts. Should I be concerned about phishing attempts after this breach? Absolutely. Be vigilant for phishing emails or messages attempting to exploit the breached data. Avoid clicking on suspicious links and verify the authenticity of any communication, especially if it asks for personal information or login credentials. Has RingCentral addressed the security issues that led to this breach? RingCentral has not provided specific details about the security measures implemented post-incident. It's advisable to monitor official statements from RingCentral or related authorities for updates on their security enhancements. Are there any legal actions being taken against the perpetrators of this breach? As of now, there is no information on legal actions. Cybersecurity agencies and law enforcement may be investigating the incident. Stay informed through official channels for any developments regarding legal proceedings. Conclusion. This breach serves as a stark reminder of the importance of robust cybersecurity practices. By staying vigilant and informed, HookPhish can better protect ourselves from similar threats.
Phishing service spoofs RingCentral to steal Microsoft 365 accounts. The Greatness phishing-as-a-service (PhaaS) platform has expanded from credential phishing to adversary-in-the-middle attacks and device-code phishing targeting Microsoft 365 accounts. The platform has been active since at least mid-2022, targeting Microsoft 365 users in the United States, Canada, the UK, Australia, and South Africa. It evolved over the years and now targets multiple platforms, including Microsoft 365, iCloud, Yahoo, and Google Workspace. Currently, it is sold for $289 per month to cybercriminals over a Telegram channel with thousands of subscribers. In a recent campaign observed by researchers at email security company ZeroBEC, Greatness operators abused the RingCentral communications platform to bypass email security filters on the recipient side. RingCentral is a communications platform used by businesses for services such as cloud calling, messaging, and voicemail. In the Greatness phishing activity, the attacker impersonated the platform by claiming their emails came from service@ringcentral[.]com, targeting actual users of the service. These emails used fake voicemail and performance-review notifications as lures to entice recipients to open them. Although the messages originated from an unknown IONOS mail server, failed SPF and DMARC checks, and had no DKIM signature, they were still accepted by the receiving systems because RingCentral was whitelisted. Moreover, the emails included a fraudulent banner claiming that the sender had been verified by the organization's safe-sender list, which helped reduce suspicion at the human level. ZeroBEC explains that the tactic achieved a Spam Confidence Level (SCL) of -1 on Microsoft Exchange, allowing them to bypass the normal email filtering stages. Clicking the button embedded in those emails took victims to the Greatness infrastructure, where they were routed either through a Microsoft adversary-in-the-middle (AiTM) phishing flow that captured an MFA-approved authentication token or through a device-code phishing flow. Post-compromise, the attacker replayed Microsoft 365 authentication tokens from VPS and commercial VPN infrastructure to access the compromised accounts. They then enumerated Outlook mailboxes, Teams conversations, SharePoint sites, OneDrive files, contacts, calendars, and registered applications through Microsoft Graph, with access persisting for more than two weeks in some cases. It should be noted that RingCentral recently disclosed a data breach incident which was claimed by threat actor ShinyHunters. "This incident has affected data for a limited portion of RingCentral customers, and we are communicating with affected customers directly," explained the company in a security bulletin published July 28. ZeroBEC comments that it's likely that cybercriminals using Greatness got a list of valid targets, users of the RingCentral platform, from that incident, though a connection cannot be confidently made. The researchers recommend auditing safe-sender lists and replacing blanket domain exclusions with rules requiring valid email authentication. Also, hunt for Greatness infrastructure and suspicious MFA-approved Microsoft 365 sign-ins from hosting or VPN addresses. If compromise is suspected, administrators should revoke all access and refresh tokens, review OAuth consent, Microsoft Graph activity, and access to Microsoft 365 services. NOTE:: ITBrands is using this article for educational or Information purpose only
Phishing service spoofs RingCentral to steal Microsoft 365 accounts. The Greatness phishing-as-a-service (PhaaS) platform has expanded from credential phishing to adversary-in-the-middle attacks and device-code phishing targeting Microsoft 365 accounts. The platform has been active since at least mid-2022, targeting Microsoft 365 users in the United States, Canada, the UK, Australia, and South Africa. It evolved over the years and now targets multiple platforms, including Microsoft 365, iCloud, Yahoo, and Google Workspace. Currently, it is sold for $289 per month to cybercriminals over a Telegram channel with thousands of subscribers. In a recent campaign observed by researchers at email security company ZeroBEC, Greatness operators abused the RingCentral communications platform to bypass email security filters on the recipient side. RingCentral is a communications platform used by businesses for services such as cloud calling, messaging, and voicemail. In the Greatness phishing activity, the attacker impersonated the platform by claiming their emails came from service@ringcentral[.]com, targeting actual users of the service. These emails used fake voicemail and performance-review notifications as lures to entice recipients to open them. Although the messages originated from an unknown IONOS mail server, failed SPF and DMARC checks, and had no DKIM signature, they were still accepted by the receiving systems because RingCentral was whitelisted. Moreover, the emails included a fraudulent banner claiming that the sender had been verified by the organization's safe-sender list, which helped reduce suspicion at the human level. ZeroBEC explains that the tactic achieved a Spam Confidence Level (SCL) of -1 on Microsoft Exchange, allowing them to bypass the normal email filtering stages. Clicking the button embedded in those emails took victims to the Greatness infrastructure, where they were routed either through a Microsoft adversary-in-the-middle (AiTM) phishing flow that captured an MFA-approved authentication token or through a device-code phishing flow. Post-compromise, the attacker replayed Microsoft 365 authentication tokens from VPS and commercial VPN infrastructure to access the compromised accounts. They then enumerated Outlook mailboxes, Teams conversations, SharePoint sites, OneDrive files, contacts, calendars, and registered applications through Microsoft Graph, with access persisting for more than two weeks in some cases. It should be noted that RingCentral recently disclosed a data breach incident which was claimed by threat actor ShinyHunters. "This incident has affected data for a limited portion of RingCentral customers, and we are communicating with affected customers directly," explained the company in a security bulletin published July 28. ZeroBEC comments that it's likely that cybercriminals using Greatness got a list of valid targets, users of the RingCentral platform, from that incident, though a connection cannot be confidently made. The researchers recommend auditing safe-sender lists and replacing blanket domain exclusions with rules requiring valid email authentication. Also, hunt for Greatness infrastructure and suspicious MFA-approved Microsoft 365 sign-ins from hosting or VPN addresses. If compromise is suspected, administrators should revoke all access and refresh tokens, review OAuth consent, Microsoft Graph activity, and access to Microsoft 365 services.
Find jobs on Simplify and start your career today
Industries
Consumer Software
Enterprise Software
Company Size
5,001-10,000
Company Stage
IPO
Headquarters
Belmont, California
Founded
2003
Find jobs on Simplify and start your career today