Threat Intelligence
The breach at RingCentral began with a phone call.
ShinyHunters claimed on 27 July that it had stolen 623 GB from the cloud communications platform. The Register reported how: the group voice-phished an employee and talked the victim into handing over a password. No zero-day. No stolen API key. No clever chain of exploits. A telephone and a convincing voice.
I have watched this pattern for years, and I still see organizations defend against everything except the attack that gets used.
The Entry Point Was a Voice
RingCentral disclosed the incident on 28 July and described a social engineering campaign that bypassed existing controls. ShinyHunters told The Register the entry was a single employee who repeated a password to a caller. The company refused the ransom, so the group published a 280 GB compressed archive on its dark web leak site around 3 August.
The uncomfortable detail for any security team is that this is the least technical intrusion of the year, and it worked.
What Was Taken
Have I Been Pwned added the breach on 13 August: 1.6 million unique accounts with names, email addresses, phone numbers, and physical addresses. RingCentral has not confirmed the number, but the HIBP figure comes from an independent analysis of the leaked data.
That is a complete contact record for phishing, vishing, and targeted impersonation against your customers, sold to whoever wants it.
What This Should Change
Voice phishing bypasses MFA. That is the lesson I keep repeating: enterprises spend on hardware keys and conditional access, then leave a path open where a caller who knows the right manager’s name is enough to extract a password.
Vishing-resistant authentication, caller verification, and drills that simulate phone-based social engineering are no longer optional controls. They are the controls the adversaries are testing.
RingCentral’s 1.6 million account exposure confirms that the most reliable initial access vector in 2026 is still a phone call, and vishing-resistant controls deserve the same priority as endpoint protection.