The call comes on a Tuesday afternoon. The person on the line uses your full name, reads back the street you live on, and says they are with your provider’s security team about unusual activity on your account. Everything they say about you is correct. That is the part that works — they have your name, your address, your mobile number and your email address, and they took all four out of the same file.
Nobody in that situation is being careless. They are being given accurate details by a stranger and drawing the obvious conclusion.
What Company Was Breached?
RingCentral is a cloud-based provider of unified communications — business phone, team messaging, video meetings and contact-centre software — and the records that were published belong to individual people, not to companies.
That distinction matters more than it sounds. Most coverage of this breach has been written for security teams, because RingCentral is something an employer buys. The file that ended up in public is a list of people, with the address each of them lives at.
When Did the Breach Occur?
RingCentral says the incident happened in July 2026 and was the result of what it calls a “sophisticated social engineering campaign,” and Have I Been Pwned records the breach date as 27 July 2026.
The sequence, from the company’s own bulletin and from reporting by SecurityWeek and BleepingComputer:
- Late July 2026 — the ShinyHunters extortion group adds RingCentral to its leak site, claiming more than 623GB of data.
- 28 July 2026 — RingCentral discloses the incident and says it has stopped the unauthorised activity.
- 3 August 2026 — with no payment made, the group publishes a 280GB archive.
- 13 August 2026 — Have I Been Pwned analyses the archive and adds it to its public database.
Between the incident and the archive being catalogued, roughly two weeks passed. During that time the data was already in circulation.
What Was Stolen?
Have I Been Pwned counted approximately 1.6 million unique email addresses in the published archive — 1,596,490 on its analysis — each one accompanied by a name, a phone number and a physical address.
The count is disputed, and it should be reported as disputed. That figure is Have I Been Pwned’s analysis of what the attackers published. RingCentral’s own notice says the incident affected “a limited portion of RingCentral customers,” that it contacted those people directly, and — in the company’s words — “if you are not contacted by RingCentral, you are not affected.” At the time of writing the company has not confirmed the attackers’ figure. Both statements are on the record and they have not been reconciled.
What was not in the published set, per the reporting: passwords, payment card numbers and bank details are not among the fields described.
How Can This Breach Be Used Against You?
The four fields published together — name, email address, phone number and home address — are the exact combination that makes a scam sound like it came from someone who already knows you.
Three concrete things that follow from a file shaped like this:
- A phone call that reads your address back to you. This is not hypothetical for this breach in particular: a ShinyHunters spokesperson told The Register the group got into RingCentral by phoning an employee and talking them into handing over a password. The same technique works on customers, and now it comes with your street name attached.
- An email that opens with your full name and a real order or account detail. Generic phishing is easy to ignore. Phishing that is accurate about you is not, and accuracy is what a leaked identity record buys.
- A text about a delivery or a payment, sent to your actual mobile number. A phone number in a breach file is a second door into the same person, and it is the one most people have no filter on at all.
The through-line is that every one of these arrives in a channel you did not open. Somebody who has your address can start a conversation with you whenever they like.
How to Protect Yourself
Most of what is worth doing here has nothing to do with any product, including ours. Do these first.
- Check the dataset directly. Enter your address at haveibeenpwned.com — it is free and does not require an account. Do this even if RingCentral has not contacted you; the company’s notification list and the published archive are two different things.
- Treat inbound calls about your accounts as unverified. Hang up and call back on the number printed on your card, your statement or the back of the physical device. A real security team will wait; a scammer will push.
- Turn on two-factor authentication on your email account before anything else. Your inbox is the recovery route into most of your other accounts, so it is the one worth hardening first.
- Change any password you have reused, starting with your bank and your primary email. A password manager turns this into a one-afternoon job instead of a permanent chore.
- Freeze your credit with the bureaus if you are in the US. It is free, it is reversible in minutes, and it blocks the specific harm — new accounts opened in your name — that a name-plus-address-plus-phone record enables.
- Slow down on anything carrying a deadline. Urgency is the one ingredient a scammer has to supply themselves, because the breach did not give it to them.
How OptMsg Helps
OptMsg cannot undo a breach at another company — what it changes is where a message sent to a leaked address ends up.
Here is the honest scope of that.
Your inbox stops being an open channel. OptMsg uses patent-pending opt-in technology: mail from a sender you have not approved is delivered to your Trash rather than your inbox. A leaked address remains leaked, and messages sent to it stop landing where you read things.
A password stolen somewhere else does not open your inbox. Your OptMsg account has no password, so a password stolen from another site can’t open your inbox. Credential stuffing needs a password to try, and there is not one on the account.
That matters most for what your inbox unlocks. Your email is how most accounts get reset. Keep that door shut and the rest stay shut with it.
And you will not lose something that mattered. The fair objection to an opt-in inbox is what happens to a message you did want. When something from an unapproved sender lands in your Trash, OptMsg checks whether many other OptMsg users have opted in to that sender as trusted — and if so, you get a push alert telling you there is a flagged message waiting, rather than finding out later.
We don’t collect your personal data to sell to advertisers, and OptMsg does not scan your emails to sell ads.
If the RingCentral file has your address in it, the address is out of your hands. What reaches you is not. You can create an account and read more about how the Secure approach works on our security-first page.
Your Inbox. Your Rules.
Frequently Asked Questions
What company was breached?
RingCentral, a cloud-based provider of unified communications including business phone, team messaging, video meetings and contact-centre software. The records that were published belong to individual people rather than to companies.
When did the RingCentral breach occur?
RingCentral says the incident happened in July 2026 and was the result of a sophisticated social engineering campaign. Have I Been Pwned records the breach date as 27 July 2026 and added the data to its database on 13 August 2026.
What data was stolen in the RingCentral breach?
Have I Been Pwned counted approximately 1.6 million unique email addresses in the published archive, each accompanied by a name, a phone number and a physical address. RingCentral has said the incident affected a limited portion of its customers and has not confirmed the attackers’ figure.
How can the RingCentral breach be used against you?
Name, email address, phone number and home address published together are the combination that makes a scam call or phishing email sound like it came from someone who already knows you. The likely follow-ons are voice phishing calls that quote your address, targeted emails using your real name, and SMS scams sent to your actual number.
What should I do if I was affected by the RingCentral breach?
Check your address at haveibeenpwned.com, treat inbound calls about your accounts as unverified and call back on a printed number, turn on two-factor authentication on your email account first, change any reused passwords, and freeze your credit with the bureaus if you are in the US.
Sources
- RingCentral Trust Center — Security Bulletin (the company’s own disclosure)
- Have I Been Pwned — RingCentral
- SecurityWeek — 1.6 Million Likely Impacted by RingCentral Data Breach
- BleepingComputer — RingCentral data breach exposed info of 1.6 million accounts
- The Register — 1.6M RingCentral accounts’ data dumped after ShinyHunters extortion attack