GoFirm
Back to Blog
Case Studies·4 min read

The vished password that turned 1.6 million RingCentral accounts into a vishing kit.

By GoFirm

On 27 July 2026, the extortion group ShinyHunters added RingCentral, the cloud communications provider, to its Tor-hosted leak site, claiming to have stolen more than 623 gigabytes of data and setting a three-day deadline for payment. RingCentral, which sells cloud-based calling, messaging and voicemail infrastructure to more than 600,000 businesses, confirmed the intrusion the next day, describing it only as a "sophisticated social engineering campaign." It did not name the entry point. A ShinyHunters spokesperson later told The Register exactly how the group got in: they called a RingCentral employee on the phone and talked them into handing over their password.

The method fits a pattern Google Mandiant has tracked across ShinyHunters clusters designated UNC6240, UNC6661 and UNC6671. An attacker calls an employee, poses as internal IT support, and directs them to a fake login page built to look identical to the company's real one. When the employee types in their credentials and their one-time authentication code, the page relays both to the attacker in real time, who logs in as the employee before the code expires, typically inside thirty seconds. Standard one-time-password multi-factor authentication does nothing to stop this. The employee is not fooled by malware or a broken cryptographic scheme; they are fooled by a caller who sounds exactly like the help desk they were trained to trust.

RingCentral refused to pay. On 3 August, ShinyHunters published a 280-gigabyte compressed archive of the stolen files. Ten days later, Have I Been Pwned analysed the dump and added it to its public breach database: approximately 1.6 million unique email addresses, each paired with the account holder's full name, phone number and physical address. RingCentral told customers that anyone not directly contacted was unaffected. HIBP's independent count of 1.6 million records, a figure RingCentral has neither confirmed nor denied, complicates that assurance considerably.

The RingCentral breach is one entry in a much longer 2026 ledger for ShinyHunters, a group affiliated with the wider Com network that also produced Scattered Spider and Lapsus$. The same vishing playbook has reportedly been used against Abbott's cancer diagnostics business (10.9 million email addresses), Odido in the Netherlands (6.5 million identity records), ADT (5.5 million people) and Carnival Cruise Line (6 million people), among others. By early 2026 the group claimed more than 1.5 billion records stolen across a single campaign wave targeting Salesforce Experience Cloud misconfigurations. None of that scale required breaking encryption or exploiting a software flaw. Every entry on the list started with a phone call an employee believed.

The defences that failed at RingCentral were not weak by conventional standards. The company runs one-time-password multi-factor authentication, the same control most enterprise security programmes treat as sufficient. It failed here for the reason it fails against every ShinyHunters vishing campaign: OTP MFA authenticates that someone has the code, not that the person on the phone is who they claim to be. A caller convincing enough to extract a password is convincing enough to extract the six digits that follow it, and the real-time relay technique gives the attacker a window measured in seconds, not enough time for suspicion to catch up with compliance.

A credential reset or a bulk export of customer records at the scale ShinyHunters achieved at RingCentral is an execution event. Before a password reset or a customer data export can complete, GoFirm sends a real-time push notification to the named authority for that system, on their own registered device, over a channel the caller on the phone has no access to. Confirmation requires a biometric response on that device: a fingerprint or face match the attacker cannot produce remotely, no matter how convincingly they impersonate IT support.

This is the structural difference between GoFirm's control and the one-time password RingCentral had in place. An OTP is a shared secret that can be phished, relayed and replayed within its validity window. A biometric confirmation on a registered device cannot be relayed by a caller on a different phone, because the confirmation never leaves that device. It does not matter how well the impersonator has been trained, how urgent the pretext, or how closely the fake login page mirrors the real one. The out-of-band channel is separate from the one the attacker is using, and the biometric check happens on hardware the attacker does not hold. A caller impersonating IT support, however convincing, cannot produce a fingerprint on a device they do not possess. The execution boundary holds regardless of how credible the impersonation appears.

GoFirm is The Authority Platform. Stop unauthorised action. Every time.

In association with Osinto.ai, the collective intelligence and governance network for Security, Resilience & Defence teams.

References

1. Gatlan, S. 2026. RingCentral data breach exposed info of 1.6 million accounts. BleepingComputer, 14 August 2026.
2. The Register. 2026. 1.6M RingCentral accounts' data dumped after ShinyHunters extortion attack. The Register, 14 August 2026.
3. Culbertson, D. 2026. RingCentral was hacked by phone call: 1.6M users' contact details now arm vishing attacks. Tech Times, 15 August 2026.
4. Bartram, N. 2026. Data breach roundup (August 14 - 20, 2026). Privacy Guides, 21 August 2026.

Share this article