RingCentral Breach Data Includes 1.6M Email Addresses, HIBP Says

HIBP says the RingCentral breach exposed 1.6 million email addresses plus names, phone numbers, and addresses, raising phishing concerns.

Written By
Kezia Jungco
Kezia Jungco
Aug 14, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

RingCentral’s July security incident is now tied to a much larger public dataset than the company initially disclosed.

Have I Been Pwned added the incident to its breach database on Aug. 13, saying leaked data contained 1.6 million unique email addresses along with names, phone numbers, and physical addresses. RingCentral previously said the incident affected only a “limited portion” of customers and that impacted customers would be contacted directly.

The exposed contact data could increase phishing risk for affected users, although researchers have not confirmed a connection between the breach and a separate campaign impersonating RingCentral to steal Microsoft 365 credentials.

HIBP puts a number on the RingCentral breach

Have I Been Pwned said RingCentral was targeted in July by a ShinyHunters “pay or leak” extortion campaign. The group later published data it claimed came from the platform, including 1.6 million unique email addresses along with names, phone numbers, and physical addresses. HIBP added the breach to its database on Aug. 13.

RingCentral had disclosed the incident on July 28, saying it discovered a sophisticated social engineering campaign and stopped the unauthorized activity after detection. The company said it brought in a third-party forensic firm and had seen no new unauthorized activity after remediation.

RingCentral said the incident affected data belonging to a limited portion of customers and that it was contacting those customers directly. 

“If you are not contacted by RingCentral, you are not affected,” the company said. RingCentral also said its core platform was not impacted and services continued without disruption.

BleepingComputer reported that the spoofed RingCentral emails failed SPF and DMARC checks and had no DKIM signature. Even so, receiving systems accepted the messages because RingCentral had been whitelisted.

Clicking the lure sent victims to Greatness infrastructure, where attackers used adversary-in-the-middle or device-code phishing to target Microsoft 365 accounts. In some cases, attackers later used stolen authentication tokens to access Outlook, Teams, SharePoint, OneDrive, and other Microsoft 365 services.

ZeroBEC said the RingCentral breach may have given Greatness operators a list of legitimate RingCentral users to target. Researchers could not verify that connection, however, so the breach and the phishing campaign remain separate incidents based on the available evidence.

Advertisement

Audit RingCentral safe-sender rules and Microsoft 365 access

ZeroBEC recommended checking safe-sender lists for blanket RingCentral exclusions. Instead of automatically trusting the domain, organizations can require messages to pass email authentication checks.

Administrators should also look for suspicious Microsoft 365 sign-ins coming from hosting providers or VPN infrastructure. If an account may have been compromised, ZeroBEC recommended revoking access and refresh tokens and reviewing OAuth consent, Microsoft Graph activity, and access to Microsoft 365 services.

For RingCentral customers, the HIBP listing adds another reason to be cautious about messages that use the company’s name. The newly cataloged breach data includes email addresses, names, phone numbers, and physical addresses, information that could make targeted phishing attempts more convincing.

For security teams, the immediate takeaway is simpler: do not let brand-based allowlisting override email-authentication failures. 

Read next: Learn how fake voicemail messages are stealing Google credentials and what users should watch for.

Kezia Jungco

Kezia Jungco is a staff writer with five years of hands-on experience testing and analyzing generative AI platforms, chatbots, and NLP tools. She writes in-depth coverage for both enterprise and consumer audiences, focusing on artificial intelligence, data analytics, CRM solutions, cloud infrastructure, cybersecurity, and emerging tech trends. Her work appears in TechRepublic, eWEEK, Datamation, TechnologyAdvice, and Selling Signals.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.