RingCentral Breach Data Includes 1.6M Email Addresses, HIBP Says

HIBP says the RingCentral breach exposed 1.6 million email addresses plus names, phone numbers, and addresses, raising phishing concerns.

Written By
KJ
Kezia Jungco
Aug 14, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

RingCentral’s July security incident is now tied to a much larger public dataset than the company initially disclosed.

Have I Been Pwned added the incident to its breach database on Aug. 13, saying leaked data contained 1.6 million unique email addresses along with names, phone numbers, and physical addresses. RingCentral previously said the incident affected only a “limited portion” of customers and that impacted customers would be contacted directly.

The exposed contact data could increase phishing risk for affected users, although researchers have not confirmed a connection between the breach and a separate campaign impersonating RingCentral to steal Microsoft 365 credentials.

HIBP puts a number on the RingCentral breach

Have I Been Pwned said RingCentral was targeted in July by a ShinyHunters “pay or leak” extortion campaign. The group later published data it claimed came from the platform, including 1.6 million unique email addresses along with names, phone numbers, and physical addresses. HIBP added the breach to its database on Aug. 13.

RingCentral had disclosed the incident on July 28, saying it discovered a sophisticated social engineering campaign and stopped the unauthorized activity after detection. The company said it brought in a third-party forensic firm and had seen no new unauthorized activity after remediation.

RingCentral said the incident affected data belonging to a limited portion of customers and that it was contacting those customers directly. 

“If you are not contacted by RingCentral, you are not affected,” the company said. RingCentral also said its core platform was not impacted and services continued without disruption.

Exposed data adds phishing risk, not a confirmed link

BleepingComputer reported that the spoofed RingCentral emails failed SPF and DMARC checks and had no DKIM signature. Even so, receiving systems accepted the messages because RingCentral had been whitelisted.

Clicking the lure sent victims to Greatness infrastructure, where attackers used adversary-in-the-middle or device-code phishing to target Microsoft 365 accounts. In some cases, attackers later used stolen authentication tokens to access Outlook, Teams, SharePoint, OneDrive, and other Microsoft 365 services.

ZeroBEC said the RingCentral breach may have given Greatness operators a list of legitimate RingCentral users to target. Researchers could not verify that connection, however, so the breach and the phishing campaign remain separate incidents based on the available evidence.

Advertisement

Audit RingCentral safe-sender rules and Microsoft 365 access

ZeroBEC recommended checking safe-sender lists for blanket RingCentral exclusions. Instead of automatically trusting the domain, organizations can require messages to pass email authentication checks.

Administrators should also look for suspicious Microsoft 365 sign-ins coming from hosting providers or VPN infrastructure. If an account may have been compromised, ZeroBEC recommended revoking access and refresh tokens and reviewing OAuth consent, Microsoft Graph activity, and access to Microsoft 365 services.

For RingCentral customers, the HIBP listing adds another reason to be cautious about messages that use the company’s name. The newly cataloged breach data includes email addresses, names, phone numbers, and physical addresses, information that could make targeted phishing attempts more convincing.

For security teams, the immediate takeaway is simpler: do not let brand-based allowlisting override email-authentication failures. 

Read next: Learn how fake voicemail messages are stealing Google credentials and what users should watch for.

KJ

Kezia Jungco is a technology writer and researcher specializing in artificial intelligence, data analytics, CRM software, cloud infrastructure, cybersecurity, and emerging business technologies. With more than five years of experience evaluating software platforms and technology solutions, she helps business leaders understand the tools and trends shaping the future of work. Kezia has extensive hands-on experience testing and analyzing generative AI platforms, chatbots, natural language processing (NLP) tools, CRM systems, and business software. Her work focuses on translating complex technologies into practical insights that help organizations make informed decisions about technology adoption, operational efficiency, and digital transformation. As a staff writer for TechnologyAdvice, Kezia covers AI innovation, business applications of machine learning, data-driven technologies, cloud computing, cybersecurity, and sales technology. Her background in journalism, research, and education enables her to combine rigorous analysis with clear, accessible reporting for both enterprise and consumer audiences. Kezia holds a bachelor's degree in Development Communication with a major in Development Journalism from the University of the Philippines Los Baños. She has also completed professional training in artificial intelligence, data privacy, and information security. Her work has been featured in TechnologyAdvice, TechRepublic, eWeek, Datamation, and Selling Signals, where she helps readers navigate a rapidly evolving technology landscape with practical, research-driven guidance.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.