On 3 August 2026, an extortion gang finished doing what extortion gangs now do as a matter of routine: it published the data it had stolen because its victim would not pay. The victim in this case was RingCentral, one of the best-known names in cloud telephony and unified communications, and the data dump — loaded into the breach-notification service Have I Been Pwned and reported in detail on 14 August 2026 — contained 1.6 million unique email addresses belonging to the company’s customers, alongside names, physical addresses and phone numbers. The gang, ShinyHunters, says it got in not by cracking a firewall or exploiting a zero-day, but by picking up the phone and talking a RingCentral employee into handing over their password.
For any UK business that runs its calls, video meetings and contact-centre queues over a hosted VoIP or unified-communications (UC) platform, that last detail is the whole story. The route in was a voice-phishing call — “vishing” — against a human being, not a machine. It is exactly the threat model that communications platforms and support desks are most exposed to, because their entire job is to answer the phone, be helpful, and reset things for people who sound like they need help. This article sets out what was taken, how the attack unfolded, why it should concern you even if you have never been a RingCentral customer, and the specific, Cyber Essentials-aligned steps a sensible UK SME should take this week.
What RingCentral actually confirmed
RingCentral disclosed the incident on 28 July 2026, describing it as a “sophisticated social engineering campaign” that affected a “limited portion” of its customers. The company said that once it detected the intrusion it moved to contain it, engaged a third-party forensic firm, and has since seen “no new unauthorised activity” in its environment. That is the reassuring half of the statement, and it deserves to be read at face value: a fast containment and an external forensic review are exactly what a mature response looks like.
The less reassuring half is the scale of what ShinyHunters claims to have carried out before containment. According to the gang — and it is worth stressing that these are the attacker’s own figures, not RingCentral’s — the haul runs to more than 623GB of data and over 30 million rows of customer information. Within that, the gang claims to hold more than 1 million Social Security numbers and 7.5 million dates of birth. For a communications provider, though, the most alarming claim is different in kind: over 22 million rows of client notes said to contain confidential doctor–patient conversations, plus more than 20 million medical-order records carrying patient identifiers and prescription details.
If that content is genuine, it reflects how deeply a modern UC platform can sit inside a customer’s operations. RingCentral is not merely a dial-tone provider; its customers include healthcare organisations that use its telephony, messaging and contact-centre tooling to run patient-facing workflows. When such a platform is breached, the exposure is not limited to a marketing list of email addresses. It can reach into the substance of what customers discuss and record over the channels the platform carries — which is precisely why communications security is a data-protection issue, not just an IT-availability one.
The mechanism here — a phone call that talks a trusted employee out of their credentials — is vendor-agnostic. Every hosted VoIP and unified-comms platform is administered by people who can be called, and every organisation that runs one has a support desk, a reception line or an IT helpdesk whose job is to be helpful to callers. That is the attack surface. ShinyHunters did not need a software vulnerability; it needed one person to believe a convincing voice. If your business relies on VoIP or UC, the right response is not to switch vendor in a panic — it is to assume your own staff will receive the same call and make sure they know what to do when they do.
How the RingCentral breach unfolded
The sequence below is compressed into little more than a fortnight, and it follows the now-familiar rhythm of a modern extortion case: quiet intrusion, disclosure, a short deadline, refusal, and publication. Dates are drawn from RingCentral’s own disclosure, ShinyHunters’ claims and the breach-notification record.
Where the real gaps sit in a typical SME
Vishing succeeds where a control is missing or a process assumes good faith. The bars below are an illustrative view of how exposed a typical UK small business tends to be across the controls that would have blunted an attack of this shape — a higher bar means a wider, more commonly observed gap, not a measured statistic for any one firm.
The human element is the common thread
What makes this breach so instructive is not its novelty but its ordinariness. Year after year, the largest share of reported breaches involve a human element — someone phished, tricked, mistaken or manipulated — rather than a purely technical failure. The RingCentral incident is a textbook example: a global platform with real security investment was undone by a single conversation. The donut below reflects that broad, well-documented pattern, and it is the reason security training belongs on the same footing as patching and firewalls.
Questions to put to your VoIP or UC provider this week
You do not need to become a penetration tester to reduce your exposure. You need to ask a handful of pointed questions — of your own staff and of your communications vendor — and to notice how confidently they are answered. The grid below ranks the questions by how much they matter after an attack of this kind. A provider or an internal process that cannot answer the “high” items clearly is telling you where your risk is concentrated.
What an exposure like this can cost a UK business
The financial shape of a communications-platform breach depends less on your headcount than on what flows through the platform — but size is still a useful proxy for exposure and for the effort a proper response demands. The bands below are indicative, in pounds sterling, and assume an organisation that has to notify, investigate and remediate rather than one that was well prepared in advance.
| Business size | Typical VoIP/UC footprint | What a comms breach can expose | Indicative cost if poorly prepared |
|---|---|---|---|
| Micro (1–9 staff) | Hosted phone lines, a shared inbox, basic call recording | Customer contact details, call logs, voicemail and message content | £3,000–£15,000 |
| Small (10–49 staff) | UC suite with Teams/voice, a small contact queue, CRM links | Client records, appointment notes, recorded calls, integration tokens | £15,000–£75,000 |
| Medium (50–249 staff) | Full contact centre, IVR, analytics, multiple integrations | Large customer datasets, transcripts, health or payment references, staff data | £75,000–£350,000 |
| Regulated (any size) | Comms carrying health, legal or financial conversations | Special-category personal data, professional-confidence records, ICO exposure | £100,000–£500,000+ |
Reactive versus proactive: two ways to hold a comms platform
Reactive posture
What most SMEs do today
- Assume the VoIP vendor’s security is entirely the vendor’s problem
- Allow support-desk and admin accounts to reset credentials on a persuasive phone call alone
- Run no regular vishing or phishing awareness training for staff who answer the phone
- Learn about a supplier breach from the news rather than from a rehearsed incident plan
- Keep call recordings and message archives reachable from the same admin logins an attacker would seize
- Have no vendor questionnaire on file and no idea how the provider secures its own staff
Proactive posture
Where Cloudswitched takes you
- Treat the comms platform as part of your security perimeter, with MFA and least privilege enforced
- Require an out-of-band call-back before any password or MFA reset is actioned
- Train front-line staff to recognise and calmly refuse a vishing call, then report it
- Hold a tested incident-response plan that includes a “supplier breached our data” scenario
- Keep recordings, notes and archives in immutable, isolated backups beyond an attacker’s reach
- Run vendor security questionnaires and align access controls to Cyber Essentials before signing
The gauge above is a reflection of a common pattern rather than a measured average: most small businesses are reasonably strong on technical controls such as firewalls and endpoint protection, but noticeably weaker on the human and process side that a vishing attack targets — call-back verification, reset authority, and staff who feel able to say no to an authoritative-sounding caller. That imbalance is exactly what ShinyHunters exploited at RingCentral, and it is the cheapest gap for most SMEs to close.
Run a five-minute exercise at your next team meeting. Ask: if someone rang our helpdesk right now, sounding stressed and senior, and asked to reset an account password or read out a one-time code, what would happen? If the honest answer is “we would probably help them,” you have found your highest-value fix. Introduce a single rule — no credential or MFA reset is ever actioned on an inbound call without an independent call-back to a number already on file — and you have neutralised the exact technique used against RingCentral, at no software cost.
The story at a glance
| Detail | What we know |
|---|---|
| Victim | RingCentral, a major cloud VoIP and unified-communications provider |
| Attacker | ShinyHunters, an established data-theft and extortion gang |
| Attack vector | Voice-phishing (vishing) an employee into handing over their password |
| Disclosed | 28 July 2026 — “sophisticated social engineering campaign”, “limited portion” of customers |
| Extortion deadline | 30 July 2026; RingCentral refused to pay |
| Data published | 3 August 2026 |
| Emails confirmed leaked | 1.6 million unique addresses, via Have I Been Pwned (14 August 2026) |
| Also exposed | Names, physical addresses, phone numbers |
| Gang’s wider claims | 623GB+, 30m+ rows, 1m+ Social Security numbers, 7.5m dates of birth |
| Most sensitive claims | 22m+ client-note rows (doctor–patient conversations); 20m+ medical-order records with patient IDs and prescriptions |
| Company response | Contained, engaged a third-party forensic firm, reports no new unauthorised activity |
| UK takeaway | Review vishing training, vendor questionnaires, incident response and Cyber Essentials access controls |
This breach is the latest in a run of incidents that all point the same way — that the suppliers, tools and people around your business are now part of its attack surface. It echoes the supply-chain lesson from the N-able N-central zero-day that reached downstream MSP customers and the way a single compromised link cascaded through the cyber attack on UK manufacturers’ supply chains. It also sits alongside the governance questions raised by AI-agent liability for UK businesses and the platform-consolidation risks explored in our look at the Microsoft Copilot app merger — while the reliance on always-on comms links underlined by the UK full-fibre usage surge only raises the stakes when those channels are breached.
Is your VoIP platform a strength or a soft target?
Cloudswitched helps UK SMEs run hosted telephony and unified comms on a foundation of MFA, least privilege and staff who know how to handle a vishing call — with the vendor due diligence and tested incident response to prove it. If you cannot answer the questions in this article, we will help you find out where you stand.
Talk to us about VoIP & Phone SystemsFrequently asked questions
Make your communications platform a hard target
From MFA and least privilege to vishing-aware support processes, vendor due diligence and immutable comms backups, Cloudswitched helps UK SMEs run VoIP and unified communications the way this breach shows they should be run. Let’s pressure-test your setup before someone else does.
Talk to us about VoIP & Phone Systems


