RingCentral customer data tied to 1.6 million accounts was exposed after a July breach, according to BleepingComputer, which cited analysis by the breach notification service Have I Been Pwned. The exposed records included names, email addresses, phone numbers, and physical addresses, according to that analysis. RingCentral, a cloud communications and collaboration provider used by more than 600,000 businesses, disclosed the incident on July 28. The company said its systems had been compromised after what it described as a “sophisticated social engineering campaign,” according to BleepingComputer’s account of the disclosure. The company said at the time that the incident affected data for a limited portion of RingCentral customers and that it was contacting affected customers directly. RingCentral also said the incident did not affect its core platform and that services continued without disruption. The company said it had not seen new unauthorized activity after remediation efforts. The attribution remains less settled. BleepingComputer reports that RingCentral has not publicly attributed the breach to a specific threat actor or hacking group. A RingCentral spokesperson did not immediately respond to BleepingComputer’s request to confirm ShinyHunters’ claims, according to the report. ShinyHunters, an extortion group, claimed responsibility on July 27 and said it had stolen 623GB of data, BleepingComputer reports. After RingCentral allegedly refused to pay a ransom to have the data destroyed, the group leaked a compressed archive containing 280GB of files on its dark web leak site, according to the same report. Have I Been Pwned later analyzed the leaked data and said it contained records for 1.6 million accounts, according to BleepingComputer. That makes the breach concrete for users and security teams: the public claim is no longer just that a threat actor says it stole data, but that an external breach-notification service found account records in the leaked material. BleepingComputer also notes that ShinyHunters has claimed or been linked to a series of other data-theft campaigns involving Salesforce customers, Snowflake customers, third-party integration providers, and, most recently, alleged attacks on more than 100 organizations involving an Oracle PeopleSoft zero-day flaw. Those broader claims are context for the group’s activity, not confirmation by RingCentral that ShinyHunters was behind this incident. Who benefits: Affected customers benefit from checking whether RingCentral has contacted them and from treating communications using names, phone numbers, email addresses, or physical addresses with extra scrutiny. Security teams get a concrete data set to watch for in credential and phishing workflows. Who's exposed: RingCentral customers whose data was in the affected subset are exposed to potential phishing, impersonation, and data-enrichment abuse. RingCentral is also exposed to customer-trust and incident-response scrutiny while attribution and access details remain limited.