Skip to content
Rush Commerce
Software & Dev3 min read

RingCentral breach: 1.6M accounts are now a vishing kit

ShinyHunters leaked names, phone numbers and addresses for 1.6M RingCentral accounts after a social-engineering breach. Why your phone vendor's data is the risk.

A breach that started with a phone call ended with a phone list. Have I Been Pwned added 1.6 million records from the RingCentral breach on August 13, drawn from an archive the ShinyHunters extortion group published after the company declined to pay. The exposed fields are names, email addresses, phone numbers, and physical addresses — which is to say, exactly the input a vishing crew needs to run the same attack again, at scale, against everyone in the file.

What actually happened

RingCentral disclosed the incident on July 28, a day after ShinyHunters claimed it. The company describes the root cause as "a sophisticated social engineering campaign" and has not published technical detail beyond that. It says it stopped the unauthorized activity on detection, has seen no new activity since remediation, and that the core RingCentral platform was not affected — services stayed up throughout.

ShinyHunters initially claimed 623GB of stolen data, then published a 280GB archive roughly a week after the first post. Have I Been Pwned's analysis of that archive produced the 1.6 million figure. SecurityWeek reports that RingCentral has not confirmed the attacker's numbers and characterizes the affected group as a limited portion of its customers. Treat 1.6 million as the leaker's count validated against the dump, not the company's.

Why your phone vendor's contact list matters for your business

Most breach coverage stops at "no passwords or payment data were taken," and most operators exhale. Do not. A verified list of business names, direct-dial numbers, and street addresses is not a consolation prize — it is the raw material for the attack that caused this breach in the first place.

The loop is the thing. Attackers talked their way into a communications provider, took its customer contact data, and now hold a pre-qualified call list of businesses known to use that provider. Every entry on it can be called by someone who already knows your vendor, your number, and your address. Caller ID will look fine, because caller ID has never been an authentication factor.

Three things to do this week, none of which require a security budget:

Write down one out-of-band callback number per vendor and per bank, and use it. Nobody who calls you gets to supply the number you verify them at.

Give your help desk a script it is allowed to refuse with. Most vishing lands on whoever resets passwords. "I'll call you back at the number on file" has to be an acceptable answer to a senior-sounding caller in a hurry.

Assume the list is permanent. Patching does not un-leak an address. This file will still be circulating in 2028.

Key takeaways

  • HIBP added 1.6 million RingCentral account records on August 13, from a 280GB archive ShinyHunters published after RingCentral refused to pay
  • Exposed fields: names, email addresses, phone numbers, physical addresses — no credentials or payment data reported
  • RingCentral disclosed on July 28, attributes the breach to a social engineering campaign, and says the core platform was unaffected
  • RingCentral has not confirmed the 1.6M figure; it comes from HIBP's analysis of the leaked archive
  • The practical risk is follow-on vishing: set out-of-band callback numbers per vendor and let your help desk refuse urgent callers

How many of your vendors hold a copy of your customer contact list? We map what leaves your stack, cut the copies you don't need, and keep verification steps in systems you control. See how we build it, or send us your vendor list.

Sources: BleepingComputer, SecurityWeek, The Register.

  • #data-breach
  • #vishing
  • #vendor-risk
  • #social-engineering
  • #security
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.