// 2 CRITICAL · 4 ZERO-DAY · 7 CVE · 4 EXPLOIT IN THE LAST 24H
ShinyHunters compromised RingCentral with a single phone call, exposing 1.6 million records and leaking 280 GB of data. The real-time vishing attack demonstrates the limits of OTP-based MFA.

RingCentral disclosed a data breach on July 28, 2026 that exposed approximately 1.6 million contact records. The attack, claimed by the ShinyHunters group, exploited no technical vulnerability in the platform: a single phone call to an employee was sufficient. The case reignites debate over the limits of OTP-based MFA against real-time social engineering, with consequences extending to the trust supply chain of cloud services.

Key Takeaways
  • 1.6 million records compromised, confirmed by Have I Been Pwned, including names, emails, phone numbers, and physical addresses
  • 623 GB of data exfiltrated per ShinyHunters' claim; 280 GB actually leaked after ransom payment was refused
  • Attack vector: vishing (voice phishing) of an employee, with real-time capture and relay of the OTP code within a 30-second window
  • No technical exploit or malware per RingCentral's security bulletin; no impact on core platform or service availability

The Mechanism: A Phone Call and a 30-Second Window

Initial access did not come via zero-day or misconfiguration. According to a ShinyHunters spokesperson contacted by The Register, the group "broke into RingCentral by voice-phishing an employee and tricking them into giving the crooks their password." The employee received a call from actors posing as IT support, using pretexting techniques that made the request credible.

TechTimes detailed the operational chain: redirection to a clone site, credential capture, MFA code generation by the victim, and immediate relay to the attacker who used it within the 30-second validity window. No flaw in the RingCentral product; the failure was human-organizational in verifying the caller's identity.

The group published the data on a leak site on August 3, 2026. Have I Been Pwned added the breach to its database on August 13, confirming "approximately 1.6 million unique email addresses" with associated names, phone numbers, and physical addresses. RingCentral stated it detected no further unauthorized activity after countermeasures were implemented.

"The company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care" — ShinyHunters, leak site (via The Register)

623 GB Exfiltrated, 280 GB Leaked: The Numbers Behind the Failed Ransom

ShinyHunters claimed exfiltration of 623 GB of data. Of the full archive, 280 GB compressed was actually released on the dark web after RingCentral refused to pay the ransom. The dossier does not specify the monetary amount of the extortion demand.

The exposed records concern contact data only: names, emails, phone numbers, physical addresses. No confirmed presence of passwords, financial information, or other sensitive data of a different nature. RingCentral publicly communicated that "if you are not contacted by RingCentral, you are not affected," limiting the scope of direct notifications relative to the total records discovered by HIBP.

In the background, RingCentral's roughly 600,000 business customers amplify the potential exposure perimeter. The compromised contact data becomes ammunition for subsequent vishing campaigns: the very nature of the breach — business telephony compromised via telephony — makes future pretexting even more credible.

The Trust Chain and the Boomerang Effect

The structural irony of the case lies in the channel: a business telephony provider breached through its own primary medium. For RingCentral customers, the dual risk is not theoretical. The exposed data — names, emails, phone numbers — are exactly the information needed to build targeted vishing calls. And the breach context provides pretexting with a plausible narrative: "we're RingCentral support, following up on customers affected by the July incident."

Bridewell BCON documented a broader vishing infrastructure, with over 100 malicious domains sharing phishing kits. Some of these domains are linked to subsequent victories published on ShinyHunters leak sites, according to research cited by Cyber Magazine. The link is marked as "most attributable" by Bridewell, not absolute certainty: it indicates recurring operational patterns rather than certain operator identity behind each domain.

As Gavin Knapp, Head of Cyber Threat Intelligence at Bridewell, observed: "Blocking one domain or responding to one phishing attempt is only part of the picture." The infrastructure is designed for resilience: shutting down a single point does not break the chain.

Why OTP MFA Is No Longer Enough

The technical core of the breach is not a vulnerability to patch. It is an architectural limit of MFA based on one-time passwords. The OTP code, by definition, must be typed by the user. If the attacker is in real-time audio communication with the victim, they can capture the code and relay it immediately, within the validity window.

TechTimes emphasized that FIDO2 passkeys would have structurally blocked this attack: cryptographic authentication is bound to the legitimate domain and is not transferable via phone call. The dossier does not specify whether RingCentral had implemented FIDO2 as an option or whether it was available for the compromised account. What is documented is that the absence of this layer allowed the OTP relay.

The case fits a pattern documented for months. ShinyHunters uses vishing as a standard vector, with techniques TechTimes linked to UNC clusters tracked by Mandiant. The citation of UNC clusters appears in the source but is not independently verifiable from others: it should be read as an indication of pattern maturity, not as formal attribution to a specific Mandiant operation on this incident.

Immediate Actions

  • Check Have I Been Pwned to see if your email addresses appear in the RingCentral breach dataset, noting that direct notification from the company did not cover the full perimeter of the 1.6 million records
  • Treat unsolicited IT support calls with suspicion, even if the caller cites the RingCentral incident: pretexting on this breach is technically trivial to construct
  • Evaluate migration from OTP MFA to FIDO2/passkey authenticators where available, to eliminate the real-time relay window that characterized this attack
  • Request documentation of anti-vishing controls applied to customer support operators from cloud communication providers in your supply chain

The Limit of Human Verification

RingCentral did not fall for a bug. It fell for a gap that no Patch Tuesday resolves: an employee's ability to verify who is on the other end of the line. The technical platform held, sensitive non-public data was contained, yet 1.6 million records still got out.

For enterprises using critical cloud services, the message is that the trust chain extends to the vendor's phone support operator. When that vendor is a telephony provider, the attack vector and the product coincide. The next vishing call RingCentral customers receive could be built on data from this very breach, with a credibility that standard technical controls cannot filter.

Information verified against cited sources and current as of publication.

Sources


Sources and references
  1. rescana.com
  2. bleepingcomputer.com
  3. theregister.com
  4. cybermagazine.com
  5. techtimes.com
  6. deals.bleepingcomputer.com