RingCentral Breach: What It Means for Your Business Phone

Imagine the call. It is a Thursday afternoon and your office manager answers. The caller introduces themselves by name, says they are from your phone provider's security team, and mentions the incident that was in the news in July. They have your office manager's name, the business address and the main number, all correct. They explain that affected accounts need their admin access re-verified, and that a code will arrive by text in a moment. Could she read it back so they can confirm she is the account holder? Nothing about that call sounds wrong, which is the whole point, and it is the kind of call that becomes much easier to make after a breach like the one RingCentral disclosed on 28 July 2026. The data taken was contact information: names, emails, phone numbers and addresses for about 1.6 million records, verified independently in August. No passwords, no payment cards and no call recordings have been reported, and the platform itself was not affected. That makes it easy to dismiss. It should not be dismissed, because accurate contact details plus the name of the company to impersonate is exactly the combination a phone scammer needs, and the group responsible has spent two years showing that a well researched phone call gets further than almost any piece of malware.

Security · After the Breach

The Breach Was in July. The Phone Calls Start Now.

RingCentral lost names, email addresses, phone numbers and street addresses for around 1.6 million records to an extortion group in July 2026. The platform kept working and no calls were intercepted, so it barely registered outside the security press. But a breach like this is not really over when the provider contains it. It is a starting gun. The list tells anyone who holds it exactly who uses which phone company, and the group behind it has built its entire reputation on convincing phone calls. Here is what happened in plain terms, the scripts we expect Australian businesses to hear over the next year, and a week of work that makes them fail.

📅 ⏱ 17 min read 🇦🇺 Australian owned · Australian network · Australian support
TL;DR

In July 2026 an extortion group called ShinyHunters took customer contact data from RingCentral through social engineering. About 1.6 million records of names, emails, phone numbers and addresses were verified after the group published them. RingCentral says its platform was not affected. The real risk is what comes next: calls, texts and emails that impersonate your phone provider using details that are genuinely correct. Expect four scripts: the security re-verification, the help desk re-enrolment, the billing change and the number transfer. They all fail against the same habit: never act on an inbound contact, always call back on a number you already had. Back it up with passkeys or hardware keys on admin accounts, port locks on mobiles, forwarding and admin audits on your phone system, and a five minute staff briefing. If personal information you hold was involved, you may have your own notification duties under the Privacy Act.

What Happened, in Plain Terms

RingCentral is one of the largest cloud phone providers in the world, carrying business calls, messaging and video for customers in many countries. In July 2026 somebody talked their way into its systems. The company's own words were "a sophisticated social engineering campaign", which means a person was deceived rather than a piece of software exploited.

On 27 July the extortion group ShinyHunters claimed responsibility, said it had taken 623GB of data, and demanded money. RingCentral disclosed the incident the following day. It said it had stopped the unauthorised activity, brought in an outside forensic firm, and that the core platform had not been touched and services were running normally. It declined to pay. The group responded by publishing a 280GB archive on its leak site.

On 13 August Have I Been Pwned, the breach checking service run by security researcher Troy Hunt, added the incident after verifying the data: 1.6 million unique email addresses, with names, phone numbers and physical addresses attached. RingCentral has said the incident affected "a limited portion" of its customers and that it is contacting the people involved directly.

1.6M
unique email addresses verified by Have I Been Pwned, each with a name, phone number and physical address.
280GB
published by the attackers after RingCentral refused to pay. They claim 623GB was taken in total.
0
reported impact on the core phone platform. Calls kept flowing and nothing verified points to intercepted calls or recordings.

What We Know and What We Do Not

We are going to be strict about this, because breach coverage has a habit of turning attacker boasts and informed guesses into facts within a couple of news cycles.

We know the timeline above, the four types of data verified, that RingCentral says its platform was not affected, and that it did not pay. We have been told by the attackers that the total theft was 623GB and that what was published is only part of it. Extortion groups inflate these numbers as a matter of routine, so treat that as a claim. We do not know how exactly the attackers got in, which internal or third party system the data came from, what the forensic investigation concluded, or how many of the records belong to Australian businesses.

The entry method is the one people most want to fill in. Many commentators have assumed it was the same voice phishing approach this group used against other organisations over the last two years. That is a reasonable guess. It is still a guess, RingCentral has not said so, and we will not present it as fact. It does not change what you should do, because the defences below work regardless of which variant of social engineering was used.

What the verified data does not include

No passwords, payment card details, call recordings or message content have been reported in the verified data. If a message tells you otherwise and asks you to act urgently, for example to reset a password through a link or to buy identity protection, be suspicious of the message rather than alarmed by it.

Who ShinyHunters Are and How They Work

ShinyHunters is the name attached to one of the most prolific data extortion operations of recent years. Whether it is one group or a loose network sharing a brand is debated. What is not debated is the method, which in 2025 and 2026 has been remarkably consistent and remarkably low tech.

In the middle of 2025 the group began phoning staff at large companies, posing as internal IT support, and guiding them through the process of approving what looked like a routine data tool for their Salesforce environment. The tool belonged to the attackers. Once an employee approved it, it had ongoing access to the company's customer records without needing a password or a second factor again. Salesforce was not hacked. Its customers' people were persuaded, one phone call at a time. Qantas was one of the organisations affected, losing data on around 5.7 million customers from a third party platform used by one of its contact centres in July 2025.

By late 2025 the approach had shifted to single sign-on accounts, the one login that opens every other system at a company. Callers posed as help desk staff and told employees their multi-factor authentication needed updating, then talked them through a convincing copy of the company login page while the attacker passed each password and code to the real site as it was typed. Security researchers counted more than a hundred organisations targeted by January 2026. Okta warned customers about phishing kits built specifically for this, ADT confirmed a breach in April 2026 after an extortion demand from the group, and McKesson disclosed an incident involving voice phishing and stolen single sign-on credentials.

The group's best tool is not code. It is a confident voice on a phone, backed by just enough accurate detail to be believed. That is why a leaked list of phone provider customers is more dangerous than it looks. It supplies the accurate detail, and it tells the caller which company to claim to be from.

What a Name, Number and Address Is Worth

On its own, each field is something you might find with ten minutes on LinkedIn. Combined, and attached to a specific provider, they change the odds of a scam call succeeding. Here is how.

It removes the guess. Most scam calls claiming to be "your telco" fail because the scammer does not know who your telco is. This list tells them.

It passes the informal security check. People trust a caller who already knows their name, their business address and their number. Worse, many support processes still use exactly those details to confirm identity. A caller who has them can pass as you to somebody else's help desk, and pass as a help desk to you.

It gives the call a reason. "We are contacting customers affected by the July incident" is a true statement about a real event. It explains why the call is happening, and it primes the person to cooperate with something security related.

It lasts. Leaked data is bought, sold and merged into larger collections. The Optus and Medibank breaches of 2022, the Qantas data of 2025 and many smaller leaks are already in circulation. This one adds a verified link between a person and the platform that carries their business calls, and it will stay useful to criminals for years.

Four Scripts to Expect

We think these four will account for most of the misuse of this kind of data. They are written the way they tend to sound, because a script your staff have already heard is one they will recognise.

ScriptHow it soundsWhat the attacker wantsThe response
The security re-verification"I am calling from your phone provider about the recent incident. We need to re-verify the account holder. I have just sent a code, can you read it back?"The one-time code that lets them reset your admin login or authorise a number transfer.Never read a code to anyone who called you. Hang up and ring the provider on the number on your invoice.
The help desk re-enrolment"It is IT support. Because of the phone provider breach we are re-enrolling everyone's authenticator. Go to this page and sign in while I stay on the line."Your staff member's single sign-on login and code, relayed live to the real site.Internal IT never asks you to sign in to a page they read out over the phone. Hang up and call IT on the known number.
The billing changeAn email that matches your account name, address and usual bill amount: "Following the incident we have moved banks. Please update our details before your next payment."Your next payment, and every one after it.Confirm any change of bank details by phone on a number you already had. Never on one in the email.
The number transferTo you: "We are moving your service to a new secure platform, you will get a transfer code, please confirm it." To your carrier, pretending to be you: "I would like to port my mobile."Control of a mobile number that receives banking or admin codes.Put a port and SIM change lock on business mobiles. Treat any transfer code you did not request as an attack in progress.

Notice that all four have the same weak point. Each depends on you acting on a contact the attacker started. The moment you end that contact and start a new one on a number you already trust, the script collapses. That one habit is worth more than any number of warning emails.

Voice cloning adds a layer to this, because a caller can now sound like someone you know. We covered how that works in our guide to AI voice cloning and vishing. The defence is the same: verification on a channel you control, not on how the voice sounds.

Your Phone System Is Part of the Attack Surface

Businesses tend to think about security in terms of email, laptops and banking. The phone system rarely makes the list. It should, because a business phone account is a surprisingly useful thing for a criminal to control.

The admin portal. Whoever has admin access can forward your main number anywhere, listen to voicemail, download call recordings, create new users and change where after hours calls go. An attacker who forwards your number can receive the verification calls your bank or suppliers make to you, which turns a phone account into a key for other accounts.

Call forwarding. A single forwarding rule on one user's extension, set quietly and left in place, can intercept callbacks for weeks. It is one of the least audited settings in most businesses.

Toll fraud. The oldest trick in phone crime is still in use: take over an account and use it to call premium or international numbers the criminals profit from, usually over a weekend. The bill arrives long after the calls.

Your numbers. Business numbers carry your reputation and, increasingly, your identity with banks and suppliers. A number moved to another provider without your approval is both an outage and a security incident.

Verification codes by SMS are only as safe as the phone number

If your phone system admin, your email or your banking still uses a text message code as the second factor, that code is as secure as the mobile number it goes to and the person reading it. Both have just become easier to target. Move the important accounts to passkeys or hardware security keys, which only work on the genuine site and cannot be read out to a caller.

A One Week Plan

This works for any business, whether or not you use RingCentral. It is written as five working days of small tasks, because that is how it actually gets done.

DayTaskTime
MondayWrite a one paragraph callback rule: any request to change access, payment details or phone settings is verified on a number we already hold. Email it to everyone and put it on the wall by reception.20 minutes
TuesdayFive minute briefing with the four scripts above. Ask staff which ones they would have fallen for. Make it clear nobody will be in trouble for hanging up on a real provider.15 minutes
WednesdayPhone system audit: list admin accounts and remove any not needed, check forwarding rules on main numbers and key staff, confirm international and premium barring, turn on login and change alerts.45 minutes
ThursdaySwitch admin accounts for phone, email, banking and domain registrar to passkeys or hardware keys where supported. Stop staff approving new third party apps without an administrator.1 to 2 hours
FridayCall your mobile carrier to add port and SIM change protection on business mobiles. Check your team's emails on haveibeenpwned.com, typed in yourself. If anything you hold may be involved, start a breach assessment and note what you checked.45 minutes

If you want a sense of what automated call screening adds on top of this, our piece on what AI security catches on the phone is honest about both the gaps it closes and the ones it does not. Human process comes first. Tools help it along.

A Note for Optus Loop Customers

Optus announced in March 2024 that RingCentral would provide its cloud communications for Australian businesses, and Optus Loop customers have been moving to the RingCentral-built platform since. To be clear, nothing published about the July incident says Optus Loop customers were among the affected records, and we are not suggesting they were.

The concern is timing. A business in the middle of a migration expects emails about new portals, calls about new logins and messages about account changes, from two companies at once. That is the easiest possible environment for a fake message to slip through, because every fake looks like just another step. If you are mid-migration, tighten the callback rule further: act only on instructions you can trace back to a number or portal you already used before the migration began.

If the migration has you weighing up whether to stay at all, our guide to your Optus Loop options sets out the choices. And if you are comparing providers more broadly, our look at RingCentral, 8x8 and Aircall alternatives covers support and data location as well as price.

When Their Breach Becomes Your Breach

It is natural to assume a supplier's breach is the supplier's problem. Australian privacy law does not always agree.

The Notifiable Data Breaches scheme covers organisations subject to the Privacy Act, which broadly means businesses with annual turnover over $3 million plus some smaller ones such as health service providers. If personal information you hold is involved in a breach that is likely to result in serious harm, and you cannot fix it before harm occurs, you must tell the affected people and the Office of the Australian Information Commissioner. If you only suspect a breach, you have 30 days to assess it.

The key word is "hold". If your business kept personal information about customers or staff in an account with a supplier, and that information was exposed, the supplier notifying people does not automatically take care of your obligation. In practice the organisations involved usually agree on a single notice. Make sure that has actually been agreed rather than assuming.

Two habits help whatever your size. Keep a short written note of what you checked, when and what you concluded, because it is the first thing a customer or regulator will ask for. And hold less. Call recordings, voicemail, transcripts, SMS history and contact directories are all personal information. Keeping them only as long as you genuinely need them is the cheapest security control there is. The small business exemption still exists as at writing, though its removal remains on the reform agenda, and from 10 December 2026 covered businesses have new disclosure duties about automated decisions, explained in our automated decisions guide. Our Origin Energy breach article works through the same obligations with a different incident.

Eight Questions for Your Provider

No honest provider will promise you it can never be breached. What you can judge is whether it has thought about the problem. Put these to yours, and to anyone quoting for your business.

  1. Where does my account data live?

    Not just the calls. The CRM, the billing system and the support desk that hold your contact details, and which countries they are in.

  2. How do you verify me before changing anything?

    If the answer is name, address and phone number, that is no longer enough. Look for a PIN, a portal initiated request or a callback to a registered contact.

  3. How will you contact me in an incident?

    A defined channel, and a commitment that a genuine notice will never ask for passwords, codes or new bank details.

  4. Can I require passkeys or hardware keys for admins?

    Optional is good. Enforceable across every admin account is better.

  5. What alerts and logs can I see?

    New logins, admin changes, forwarding changes and new devices, with alerts you can send to an email address someone actually reads.

  6. How do you protect my numbers from unauthorised porting?

    Authorisation checks, notice to your registered contact, and a lock you can apply.

  7. Who on your side can see my data?

    Access limited by role, logged, and ideally held and supported in Australia.

  8. Tell me about your last incident.

    A provider that can talk plainly about what went wrong and what changed is worth more than one that claims a spotless record.

Should This Put You Off Cloud Phones?

Not in our view, and not just because we sell them. The RingCentral breach did not involve the phone platform. It involved customer records and a person who was deceived. A phone system on a shelf in your comms cupboard does not remove either of those, because you would still have a supplier holding your account details and a support line that can be rung.

What an older on-premises system adds is a set of problems a well run cloud platform takes away: firmware that has not been updated in years, passwords nobody changed from the default, no audit trail, no login alerts, no way to add modern authentication, and fraud that runs all weekend because nobody is watching. Those remain some of the most common routes to phone fraud losses for small businesses.

The sharper lesson is about what to evaluate. Phone security used to mean the network. It now means the network plus the provider's people, its support processes and the systems where it keeps your details. Ask about all of them.

How VOCPhone Handles This

Everything in this article applies to us as much as to anyone, and we would rather say that plainly. Here is how we are set up.

VOCPhone is Australian owned and runs its own network rather than reselling someone else's, which means fewer parties between you and your service and fewer places your details can sit. Your calls, recordings and account data are hosted in Australia, and our support team is Australian and human, reachable 24/7. We verify account holders before making changes, and requests to alter admin access, forwarding or numbers are confirmed through registered contacts, not on the strength of an inbound call. The portal keeps logs of logins and changes, and international and premium destinations can be barred by default.

We will never ask for a password, a one-time code or a change of bank details over the phone or in an incident notice. If anyone claiming to be VOCPhone does, hang up and call us on 1300 663 222. We will not mind at all.

And if you would like a second opinion on your current setup, with us or anyone else, we are happy to walk through the one week plan with you. Admin accounts, authentication, forwarding, barring, port locks, and what your provider holds about you. Half an hour, no obligation.

Get a second opinion on your phone security

Talk to our Australian team about admin access, MFA, call forwarding, number port protection and where your data lives. Useful whichever provider you are with today.

Talk to us Or call 1300 663 222

Frequently Asked Questions

Is the RingCentral breach serious if only contact details were taken?
Yes, although not in the way people first assume. Nothing verified suggests calls were intercepted, recordings were taken or the platform was disrupted, and RingCentral says its core platform was not affected. The verified data is names, email addresses, phone numbers and physical addresses for about 1.6 million records. The seriousness comes from what that data enables. Most scam calls claiming to be your phone company fail because the caller is guessing which company you use. This list removes the guess, supplies correct personal details that make the caller sound legitimate, and comes with a genuine news event to explain why they are calling. Many support processes also still use name, address and phone number to confirm identity, so the same data helps a criminal impersonate you to someone else. Leaked data is traded and merged into larger collections, so expect it to be used for a long time, not just in the weeks after the breach. The right response is not alarm. It is a few specific habits and settings that make these calls fail.
How did hackers get into RingCentral?
RingCentral has said only that the incident was caused by a sophisticated social engineering campaign, meaning a person was deceived rather than a software flaw exploited. The specific technique has not been disclosed. Many observers have assumed it followed the pattern the ShinyHunters group used against other organisations in 2025 and 2026: phoning staff while posing as IT support, then either persuading them to approve an attacker controlled application against a CRM such as Salesforce, or walking them through a fake single sign-on page while relaying their login and code to the real site. That is a reasonable hypothesis given the group's history, but it is unconfirmed and should not be stated as fact. What is confirmed is that the group claimed the breach on 27 July 2026, RingCentral disclosed it on 28 July and declined to pay, a 280GB archive was published, and Have I Been Pwned verified 1.6 million unique email addresses on 13 August. The defences that matter work regardless of the exact variant used.
What scam calls should I expect after the RingCentral breach?
Four scripts are the most likely. The security re-verification, where a caller claims to be from your provider about the incident and asks you to read back a code they have just sent, which is really the code to reset your admin login or authorise a number transfer. The help desk re-enrolment, where someone posing as IT support asks a staff member to sign in on a page they read out while staying on the line, relaying the login to the real site. The billing change, an email matching your account name, address and usual amount that says the provider has changed bank details. And the number transfer, where you are asked to confirm a transfer code, or the criminal contacts your mobile carrier pretending to be you. All four depend on you acting on a contact the attacker started. End the contact and start a new one on a number you already had, such as the one on your invoice or in your portal, and each script collapses. Never read a code to someone who called you, and treat any transfer code you did not request as an attack in progress.
Is my phone system a security risk?
It is part of your attack surface, and most businesses do not treat it that way. Whoever controls the admin portal can forward your main number anywhere, listen to voicemail, download recordings, create users and change after hours routing. Forwarding your number lets an attacker receive the verification calls your bank or suppliers make to you, which turns a phone account into a key for other accounts. A single forwarding rule on one extension can intercept callbacks for weeks without anyone noticing. Toll fraud, where a compromised account is used to call premium or international numbers over a weekend, remains common. And your numbers are increasingly part of your identity with banks and suppliers, so an unauthorised port is both an outage and a security incident. The practical fixes are straightforward: limit and review admin accounts, require passkeys or hardware keys for admin logins, audit forwarding rules, turn on login and change alerts, bar international and premium destinations unless you need them, and ask your carrier for port protection on business mobiles.
Should Optus Loop customers be worried about the RingCentral breach?
Nothing published about the July 2026 incident says Optus Loop customers were among the affected records, and there is no reason to assume they were. The link is that Optus announced in March 2024 that RingCentral would provide its cloud communications for Australian businesses, and Optus Loop customers have been moving to the RingCentral-built platform. The realistic concern is timing. A business mid-migration is already expecting emails about new portals, calls about new logins and messages about account changes from two companies, which is the easiest environment for a fake message to blend in. If that is you, only act on instructions you can trace to a number or portal you already used before the migration started, and verify anything involving codes, logins, payment details or number changes by ringing back on a number you already held. If the migration has you reconsidering your provider, make that decision on service, support and price, not in response to a phone call or email that arrived out of the blue.
Do I have to notify anyone if my supplier had a data breach?
Possibly. The Notifiable Data Breaches scheme applies to organisations covered by the Privacy Act, broadly businesses with annual turnover above $3 million plus some smaller ones such as health service providers. If personal information you hold is involved in a breach likely to cause serious harm, and you cannot prevent that harm through remedial action, you must notify the affected individuals and the Office of the Australian Information Commissioner. If you only suspect an eligible breach, you must take reasonable steps to assess it within 30 days. When the breach happens at a supplier, the question is whether it involved personal information your business held, for example customer or staff details kept in your account with that supplier. The supplier notifying people does not automatically discharge your obligation, although organisations involved in the same incident usually agree on a single notice. Confirm that agreement exists, and keep a short record of what you checked and concluded. The small business exemption still exists as at writing, though its removal remains on the government's reform agenda.
Are cloud phone systems less secure than on-premises systems?
Generally no, and the RingCentral breach does not change that. The incident did not involve the phone platform itself. It involved customer records and a person who was deceived, and an on-premises system does not remove either risk, because you would still have a supplier holding your account details and a support line that can be phoned. What an older on-premises system typically adds are risks a well run cloud platform removes: firmware left unpatched for years, default passwords never changed, no audit logs, no login alerts, no support for modern authentication like passkeys, and fraud that can run all weekend because nobody is monitoring. Those remain among the most common routes to phone fraud losses for small businesses. The better lesson from 2026 is about what to evaluate when choosing a provider. Security now depends on the provider's people, support processes and the systems where it keeps your details, as well as its network. Ask where your account data lives, how support staff verify you, whether admins can be required to use passkeys, and how number porting is protected.

What to Read Next

Your next reads

VOCPhone, the Australian-owned cloud phone platform that owns and operates its own network. vocphone.com | 1300 663 222

Related Articles