RingCentral’s July security incident is now tied to a much larger public dataset than the company initially disclosed.
Have I Been Pwned added the incident to its breach database on Aug. 13, saying leaked data contained 1.6 million unique email addresses along with names, phone numbers, and physical addresses. RingCentral previously said the incident affected only a “limited portion” of customers and that impacted customers would be contacted directly.
The exposed contact data could increase phishing risk for affected users, although researchers have not confirmed a connection between the breach and a separate campaign impersonating RingCentral to steal Microsoft 365 credentials.
HIBP puts a number on the RingCentral breach
Have I Been Pwned said RingCentral was targeted in July by a ShinyHunters “pay or leak” extortion campaign. The group later published data it claimed came from the platform, including 1.6 million unique email addresses along with names, phone numbers, and physical addresses. HIBP added the breach to its database on Aug. 13.
RingCentral had disclosed the incident on July 28, saying it discovered a sophisticated social engineering campaign and stopped the unauthorized activity after detection. The company said it brought in a third-party forensic firm and had seen no new unauthorized activity after remediation.
RingCentral said the incident affected data belonging to a limited portion of customers and that it was contacting those customers directly.
“If you are not contacted by RingCentral, you are not affected,” the company said. RingCentral also said its core platform was not impacted and services continued without disruption.
Exposed data adds phishing risk, not a confirmed link
BleepingComputer reported that the spoofed RingCentral emails failed SPF and DMARC checks and had no DKIM signature. Even so, receiving systems accepted the messages because RingCentral had been whitelisted.
Clicking the lure sent victims to Greatness infrastructure, where attackers used adversary-in-the-middle or device-code phishing to target Microsoft 365 accounts. In some cases, attackers later used stolen authentication tokens to access Outlook, Teams, SharePoint, OneDrive, and other Microsoft 365 services.
ZeroBEC said the RingCentral breach may have given Greatness operators a list of legitimate RingCentral users to target. Researchers could not verify that connection, however, so the breach and the phishing campaign remain separate incidents based on the available evidence.
Audit RingCentral safe-sender rules and Microsoft 365 access
ZeroBEC recommended checking safe-sender lists for blanket RingCentral exclusions. Instead of automatically trusting the domain, organizations can require messages to pass email authentication checks.
Administrators should also look for suspicious Microsoft 365 sign-ins coming from hosting providers or VPN infrastructure. If an account may have been compromised, ZeroBEC recommended revoking access and refresh tokens and reviewing OAuth consent, Microsoft Graph activity, and access to Microsoft 365 services.
For RingCentral customers, the HIBP listing adds another reason to be cautious about messages that use the company’s name. The newly cataloged breach data includes email addresses, names, phone numbers, and physical addresses, information that could make targeted phishing attempts more convincing.
For security teams, the immediate takeaway is simpler: do not let brand-based allowlisting override email-authentication failures.
Read next: Learn how fake voicemail messages are stealing Google credentials and what users should watch for.





