Ransomware victim disclosure
← All victimsRingCentral, Inc.
Claimed by Shinyhunters · listed 2 days ago
Status timeline
- ListedJul 27, 2026
- Data leakeddate unknown
At a glance
- Group
- Shinyhunters
- Status
- Data leaked
- Country
- United States
- Sector
- Technology
- Listed on leak site
- Jul 27, 2026
About the victim
AI dossier — public-source company profileRingCentral is a cloud-based unified communications platform serving over 600,000 businesses globally. The company provides voice, video, messaging, and AI-powered customer interaction solutions for small businesses through enterprises.
- Industry
- Cloud Communications & Unified Communications Platform
Attack summary
Severity: high — RingCentral is a major communications platform with 600,000+ business customers. Breach of their systems likely exposes sensitive business communications, customer data, and potentially PII at scale across diverse industries. No specific proof files are advertised, but the threat actor's final deadline and escalation language suggests confirmed exfiltration.shinyhunters claims to have compromised an unspecified volume of RingCentral data and issued a final extortion demand with a 30 July 2026 deadline, threatening to publish stolen data and cause additional operational disruption.
Data the group says was taken
AI dossier — extracted from the leak post- business communications data
- customer account information
What the group claims
Over XX of data was compromised. This is a final warning to reach out by 30 July 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 27 July 2026 | Warning: FINAL WARNING PAY OR LEAK
Sources
- Victim siteringcentral.com
Source
Indexed 2 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

