Back to News

1.6 Million RingCentral Accounts Leaked After Vishing Attack: What It Means for UK VoIP Users

1.6 Million RingCentral Accounts Leaked After Vishing Attack: What It Means for UK VoIP Users

On 3 August 2026, an extortion gang finished doing what extortion gangs now do as a matter of routine: it published the data it had stolen because its victim would not pay. The victim in this case was RingCentral, one of the best-known names in cloud telephony and unified communications, and the data dump — loaded into the breach-notification service Have I Been Pwned and reported in detail on 14 August 2026 — contained 1.6 million unique email addresses belonging to the company’s customers, alongside names, physical addresses and phone numbers. The gang, ShinyHunters, says it got in not by cracking a firewall or exploiting a zero-day, but by picking up the phone and talking a RingCentral employee into handing over their password.

For any UK business that runs its calls, video meetings and contact-centre queues over a hosted VoIP or unified-communications (UC) platform, that last detail is the whole story. The route in was a voice-phishing call — “vishing” — against a human being, not a machine. It is exactly the threat model that communications platforms and support desks are most exposed to, because their entire job is to answer the phone, be helpful, and reset things for people who sound like they need help. This article sets out what was taken, how the attack unfolded, why it should concern you even if you have never been a RingCentral customer, and the specific, Cyber Essentials-aligned steps a sensible UK SME should take this week.

1.6m
Unique customer email addresses confirmed leaked by Have I Been Pwned — with names, physical addresses and phone numbers attached
623GB
Volume of data ShinyHunters claims to have exfiltrated — more than 30 million rows of customer information in total
1 call
The attack began with a single voice-phishing call that tricked one employee into surrendering their password
3 Aug
The date the gang published the stolen data after RingCentral refused to pay before its 30 July deadline

What RingCentral actually confirmed

RingCentral disclosed the incident on 28 July 2026, describing it as a “sophisticated social engineering campaign” that affected a “limited portion” of its customers. The company said that once it detected the intrusion it moved to contain it, engaged a third-party forensic firm, and has since seen “no new unauthorised activity” in its environment. That is the reassuring half of the statement, and it deserves to be read at face value: a fast containment and an external forensic review are exactly what a mature response looks like.

The less reassuring half is the scale of what ShinyHunters claims to have carried out before containment. According to the gang — and it is worth stressing that these are the attacker’s own figures, not RingCentral’s — the haul runs to more than 623GB of data and over 30 million rows of customer information. Within that, the gang claims to hold more than 1 million Social Security numbers and 7.5 million dates of birth. For a communications provider, though, the most alarming claim is different in kind: over 22 million rows of client notes said to contain confidential doctor–patient conversations, plus more than 20 million medical-order records carrying patient identifiers and prescription details.

If that content is genuine, it reflects how deeply a modern UC platform can sit inside a customer’s operations. RingCentral is not merely a dial-tone provider; its customers include healthcare organisations that use its telephony, messaging and contact-centre tooling to run patient-facing workflows. When such a platform is breached, the exposure is not limited to a marketing list of email addresses. It can reach into the substance of what customers discuss and record over the channels the platform carries — which is precisely why communications security is a data-protection issue, not just an IT-availability one.

Why this matters to you even if you never used RingCentral

The mechanism here — a phone call that talks a trusted employee out of their credentials — is vendor-agnostic. Every hosted VoIP and unified-comms platform is administered by people who can be called, and every organisation that runs one has a support desk, a reception line or an IT helpdesk whose job is to be helpful to callers. That is the attack surface. ShinyHunters did not need a software vulnerability; it needed one person to believe a convincing voice. If your business relies on VoIP or UC, the right response is not to switch vendor in a panic — it is to assume your own staff will receive the same call and make sure they know what to do when they do.

How the RingCentral breach unfolded

The sequence below is compressed into little more than a fortnight, and it follows the now-familiar rhythm of a modern extortion case: quiet intrusion, disclosure, a short deadline, refusal, and publication. Dates are drawn from RingCentral’s own disclosure, ShinyHunters’ claims and the breach-notification record.

Initial access — a vishing call
ShinyHunters says it obtained its foothold by voice-phishing a RingCentral employee — calling by phone and persuading the individual to hand over their password. No malware or unpatched flaw was needed for the first step; the credential opened the door.
28 July 2026 — RingCentral discloses
The company publicly describes a “sophisticated social engineering campaign” affecting a “limited portion” of customers, and says it has contained the activity and brought in a third-party forensic firm.
30 July 2026 — extortion deadline
ShinyHunters sets a deadline for RingCentral to pay an extortion demand, threatening to publish the stolen dataset if the company does not comply.
30 July 2026 — the company refuses
RingCentral declines to pay. Refusing extortion is the position law enforcement and the NCSC consistently recommend, but it comes with the near-certain consequence that the data will be released.
3 August 2026 — the data is published
With the deadline passed and no payment made, the gang releases the stolen data online, claiming over 623GB and more than 30 million rows including Social Security numbers, dates of birth, client notes and medical-order records.
14 August 2026 — 1.6m emails confirmed
Have I Been Pwned loads 1.6 million unique RingCentral-linked email addresses — with names, physical addresses and phone numbers — and the breach is reported in detail in the technology press, giving affected individuals a way to check their exposure.
15 August 2026 — UK businesses take stock
With the facts settled, the practical question for UK SMEs shifts from “what happened” to “could the same call work on us” — and what controls would stop it.

Where the real gaps sit in a typical SME

Vishing succeeds where a control is missing or a process assumes good faith. The bars below are an illustrative view of how exposed a typical UK small business tends to be across the controls that would have blunted an attack of this shape — a higher bar means a wider, more commonly observed gap, not a measured statistic for any one firm.

Staff vishing-awareness training
88%
Call-back verification on reset requests
82%
MFA on admin & support-desk accounts
71%
Least privilege on reset/call authority
69%
Vendor security questionnaires in use
74%
Tested incident-response plan
66%
Immutable, isolated comms backups
58%

The human element is the common thread

What makes this breach so instructive is not its novelty but its ordinariness. Year after year, the largest share of reported breaches involve a human element — someone phished, tricked, mistaken or manipulated — rather than a purely technical failure. The RingCentral incident is a textbook example: a global platform with real security investment was undone by a single conversation. The donut below reflects that broad, well-documented pattern, and it is the reason security training belongs on the same footing as patching and firewalls.

74%
Illustrative share of reported breaches that involve a human element — phishing, social engineering or error — rather than a purely technical exploit. The RingCentral vishing attack sits squarely in this majority.

Questions to put to your VoIP or UC provider this week

You do not need to become a penetration tester to reduce your exposure. You need to ask a handful of pointed questions — of your own staff and of your communications vendor — and to notice how confidently they are answered. The grid below ranks the questions by how much they matter after an attack of this kind. A provider or an internal process that cannot answer the “high” items clearly is telling you where your risk is concentrated.

Where the biggest gaps usually hide — ranked by priority
Is MFA enforced on every admin and support-desk account with call, reset or configuration authority? High
Do staff know how to recognise and refuse a vishing call requesting a password or reset? High
Is there an out-of-band call-back step before any credential or MFA reset is actioned? High
Does the VoIP/UC vendor publish how it secures its own support staff against social engineering? High
Is least privilege applied so no single account can export the full customer or call dataset? Mid
Do you send and review a vendor security questionnaire before and during the contract? Mid
Has your incident-response plan been tested against a “supplier breached our data” scenario? Mid
Are call recordings, notes and message archives backed up immutably and isolated from admin access? Low

What an exposure like this can cost a UK business

The financial shape of a communications-platform breach depends less on your headcount than on what flows through the platform — but size is still a useful proxy for exposure and for the effort a proper response demands. The bands below are indicative, in pounds sterling, and assume an organisation that has to notify, investigate and remediate rather than one that was well prepared in advance.

Business size Typical VoIP/UC footprint What a comms breach can expose Indicative cost if poorly prepared
Micro (1–9 staff) Hosted phone lines, a shared inbox, basic call recording Customer contact details, call logs, voicemail and message content £3,000–£15,000
Small (10–49 staff) UC suite with Teams/voice, a small contact queue, CRM links Client records, appointment notes, recorded calls, integration tokens £15,000–£75,000
Medium (50–249 staff) Full contact centre, IVR, analytics, multiple integrations Large customer datasets, transcripts, health or payment references, staff data £75,000–£350,000
Regulated (any size) Comms carrying health, legal or financial conversations Special-category personal data, professional-confidence records, ICO exposure £100,000–£500,000+

Reactive versus proactive: two ways to hold a comms platform

Reactive posture

What most SMEs do today

  • Assume the VoIP vendor’s security is entirely the vendor’s problem
  • Allow support-desk and admin accounts to reset credentials on a persuasive phone call alone
  • Run no regular vishing or phishing awareness training for staff who answer the phone
  • Learn about a supplier breach from the news rather than from a rehearsed incident plan
  • Keep call recordings and message archives reachable from the same admin logins an attacker would seize
  • Have no vendor questionnaire on file and no idea how the provider secures its own staff

Proactive posture

Where Cloudswitched takes you

  • Treat the comms platform as part of your security perimeter, with MFA and least privilege enforced
  • Require an out-of-band call-back before any password or MFA reset is actioned
  • Train front-line staff to recognise and calmly refuse a vishing call, then report it
  • Hold a tested incident-response plan that includes a “supplier breached our data” scenario
  • Keep recordings, notes and archives in immutable, isolated backups beyond an attacker’s reach
  • Run vendor security questionnaires and align access controls to Cyber Essentials before signing
38
Typical SME vishing-readiness score (illustrative, out of 100)

The gauge above is a reflection of a common pattern rather than a measured average: most small businesses are reasonably strong on technical controls such as firewalls and endpoint protection, but noticeably weaker on the human and process side that a vishing attack targets — call-back verification, reset authority, and staff who feel able to say no to an authoritative-sounding caller. That imbalance is exactly what ShinyHunters exploited at RingCentral, and it is the cheapest gap for most SMEs to close.

A practical first step this week

Run a five-minute exercise at your next team meeting. Ask: if someone rang our helpdesk right now, sounding stressed and senior, and asked to reset an account password or read out a one-time code, what would happen? If the honest answer is “we would probably help them,” you have found your highest-value fix. Introduce a single rule — no credential or MFA reset is ever actioned on an inbound call without an independent call-back to a number already on file — and you have neutralised the exact technique used against RingCentral, at no software cost.

The story at a glance

Detail What we know
Victim RingCentral, a major cloud VoIP and unified-communications provider
Attacker ShinyHunters, an established data-theft and extortion gang
Attack vector Voice-phishing (vishing) an employee into handing over their password
Disclosed 28 July 2026 — “sophisticated social engineering campaign”, “limited portion” of customers
Extortion deadline 30 July 2026; RingCentral refused to pay
Data published 3 August 2026
Emails confirmed leaked 1.6 million unique addresses, via Have I Been Pwned (14 August 2026)
Also exposed Names, physical addresses, phone numbers
Gang’s wider claims 623GB+, 30m+ rows, 1m+ Social Security numbers, 7.5m dates of birth
Most sensitive claims 22m+ client-note rows (doctor–patient conversations); 20m+ medical-order records with patient IDs and prescriptions
Company response Contained, engaged a third-party forensic firm, reports no new unauthorised activity
UK takeaway Review vishing training, vendor questionnaires, incident response and Cyber Essentials access controls

This breach is the latest in a run of incidents that all point the same way — that the suppliers, tools and people around your business are now part of its attack surface. It echoes the supply-chain lesson from the N-able N-central zero-day that reached downstream MSP customers and the way a single compromised link cascaded through the cyber attack on UK manufacturers’ supply chains. It also sits alongside the governance questions raised by AI-agent liability for UK businesses and the platform-consolidation risks explored in our look at the Microsoft Copilot app merger — while the reliance on always-on comms links underlined by the UK full-fibre usage surge only raises the stakes when those channels are breached.

Is your VoIP platform a strength or a soft target?

Cloudswitched helps UK SMEs run hosted telephony and unified comms on a foundation of MFA, least privilege and staff who know how to handle a vishing call — with the vendor due diligence and tested incident response to prove it. If you cannot answer the questions in this article, we will help you find out where you stand.

Talk to us about VoIP & Phone Systems

Frequently asked questions

What is vishing, and how is it different from phishing?
Vishing is voice-phishing — social engineering carried out over a phone call rather than by email. Where a phishing email tries to lure you into clicking a link or entering credentials on a fake page, a vishing call uses a live human voice to build trust, apply pressure and talk the target into handing something over directly, such as a password or a one-time code. It is harder to filter than email because there is no attachment or URL to scan, and it exploits the natural instinct to be helpful to a caller who sounds legitimate and urgent. The RingCentral breach began with exactly this technique.
Was I affected if my business uses RingCentral?
RingCentral described the breach as affecting a “limited portion” of customers, but Have I Been Pwned has confirmed 1.6 million unique email addresses in the leaked data, along with names, physical addresses and phone numbers. The most direct way to check personal exposure is to search your email addresses on Have I Been Pwned. If your organisation is a RingCentral customer, treat the incident as a prompt to rotate admin credentials, confirm MFA is enforced, watch for follow-on phishing that references the breach, and ask RingCentral directly what data of yours was involved.
Who are ShinyHunters?
ShinyHunters is a well-known cybercriminal group with a long track record of stealing large volumes of data and then extorting the victim organisation, publishing the data if payment is not made. In this case the gang set a deadline of 30 July 2026, and when RingCentral refused to pay it released the stolen dataset on 3 August. Their reliance on social engineering rather than exotic technical exploits is characteristic: it is cheaper, faster and often more reliable than hunting for software vulnerabilities.
RingCentral says it contained the breach — is the risk over?
Containment stops further theft, but it does not un-publish data that is already public. RingCentral says it has seen no new unauthorised activity since remediation and is working with a third-party forensic firm, which is the right response to the intrusion itself. The lasting risk, however, is that the leaked personal details — emails, addresses, phone numbers and, per the gang’s claims, far more sensitive records — can now fuel targeted phishing, vishing and identity fraud against the affected individuals for a long time to come. That downstream risk is exactly why staff awareness matters more than ever after a breach like this.
How could handing over one password lead to a breach this large?
Modern platforms concentrate access. A single employee account — particularly one with administrative or support-tooling reach — can often see or export data belonging to very large numbers of customers, because that is what the role needs to function. When an attacker captures such an account and there is no second factor to stop them, they inherit that reach instantly. This is why two controls matter so much: multi-factor authentication, so a stolen password alone is not enough, and least privilege, so no single account can export the entire customer dataset in one action.
Would multi-factor authentication have stopped this?
MFA dramatically raises the bar, and in many cases stops a stolen-password attack outright. It is not a magic shield — determined attackers sometimes try to talk targets through reading out a one-time code, or bombard them with prompts until they approve one — but it converts “one password and you are in” into a much harder, noisier problem. Combined with phishing-resistant methods where possible, and with staff trained never to read a code to a caller, MFA remains one of the highest-value, lowest-cost controls a UK SME can put in place, and it is a core Cyber Essentials requirement.
How does Cyber Essentials relate to an attack like this?
Cyber Essentials is the UK government-backed scheme that sets a baseline of five technical controls, including secure configuration, access control and multi-factor authentication on administrative and cloud accounts. An organisation genuinely aligned to it would have MFA on the admin and support accounts a vishing attacker targets, and least-privilege access limiting what any one account can reach. Certification is not a guarantee against social engineering, but the controls it mandates directly address the mechanics of this breach, and pursuing it is a structured way to close the gaps this incident exposes.
What should our support desk do differently tomorrow?
Introduce one firm rule: no password reset, MFA reset or account change is ever actioned on the strength of an inbound call alone. Instead, the agent ends the call and rings the requester back on a number already held on file before doing anything. Pair that with permission for staff to say no — make it explicit that refusing or pausing to verify a senior-sounding caller will never be held against them. Those two changes cost nothing and directly disrupt the technique used against RingCentral.
Should we drop our VoIP provider over this?
Not as a reflex. Every major communications provider is a target for social engineering, and switching vendor does not remove the risk that your own staff will receive a similar call. A more useful response is due diligence: ask your provider how it protects its own support staff against vishing, whether it enforces MFA and least privilege internally, and how it would notify and support you in a breach. Use a vendor security questionnaire to capture the answers. If a provider cannot answer clearly, that tells you something — but the first place to strengthen is usually your own processes.
Where does cloud backup fit into protecting our communications data?
Call recordings, voicemail, chat archives and contact-centre notes are business data, and they deserve the same backup discipline as your files and email. Immutable, isolated backups — copies that cannot be altered or deleted, and that are not reachable from the same admin logins an attacker would seize — mean that even if a platform account is compromised, you retain a trustworthy record for investigation, regulatory notification and recovery. It will not prevent a breach, but it ensures a breach cannot also erase the evidence and history you would need afterwards.

Make your communications platform a hard target

From MFA and least privilege to vishing-aware support processes, vendor due diligence and immutable comms backups, Cloudswitched helps UK SMEs run VoIP and unified communications the way this breach shows they should be run. Let’s pressure-test your setup before someone else does.

Talk to us about VoIP & Phone Systems
Tags:VoIPCyber EssentialsIT SupportCloud Backup
CloudSwitched

London-based managed IT services provider offering support, cloud solutions and cybersecurity for SMEs.

CloudSwitched Service

VoIP & Phone Systems

Hosted telephony, Teams Voice and modern business communication solutions

Learn More

Technology Stack

Powered by industry-leading technologies including SolarWinds, Cloudflare, BitDefender, AWS, Microsoft Azure, and Cisco Meraki to deliver secure, scalable, and reliable IT solutions.

SolarWinds
Cloudflare
BitDefender
AWS
Hono
Opus
Office 365
Microsoft
Cisco Meraki
Microsoft Azure

Latest Articles

23
  • AI

AI Code Review: A UK Development Team's Guide to Using AI Without Introducing Technical Debt in 2026

23 Aug, 2026

AI code review has moved from novelty to default in UK development teams inside about eighteen months. Pull requests now arrive pre-annotated by a model,...

Read more
22
  • Google Ads & PPC

Google Ads Budget Waste: A UK Business Guide to Cutting Wasted PPC Spend in 2026

22 Aug, 2026

Google Ads wasted spend is the single most recoverable line item in most UK SME marketing budgets. It is not a strategy problem and it is rarely a creative...

Read more
21
  • Cyber Security

Cyber Essentials Certification: A UK Business Step-by-Step Guide to Passing First Time in 2026

21 Aug, 2026

Cyber Essentials certification has quietly become a commercial requirement rather than a security badge. It is mandatory for most central government contracts...

Read more

Enquiry Received!

Thank you for getting in touch. A member of our team will review your enquiry and get back to you within 24 hours.