What Is Actually Known
The sequence is short and well documented, and it is worth getting exactly right because a lot of secondhand coverage has blurred it.
| Date | Event | Source |
|---|---|---|
| July 2026 | Attackers gain access to RingCentral systems through what the company calls a sophisticated social engineering campaign. | RingCentral notice |
| 27 July | ShinyHunters claims the breach on its leak site, says it holds 623GB of data, and demands payment. | Attacker claim, reported by security press |
| 28 July | RingCentral publicly discloses the incident, says it stopped the unauthorised activity, has engaged a third party forensic firm, and that the core platform and services were not affected. | RingCentral notice |
| Early August | RingCentral does not pay. ShinyHunters publishes a 280GB compressed archive. | Attacker leak site, reported by security press |
| 13 August | Have I Been Pwned adds the breach: 1.6 million unique email addresses, with names, phone numbers and physical addresses. | Independent verification |
RingCentral's own description is that the incident affected "a limited portion" of its customers and that it has been contacting the people involved directly. It has also said it has seen no further unauthorised activity since containing the incident. Those statements are consistent with what has been independently verified: a large volume of customer contact records, not a compromise of the phone service itself.
That distinction matters, and it cuts both ways. Nobody's calls were being listened to and no business lost its phones. But "only contact data" is also the phrase that tends to make people stop paying attention, and that is exactly the wrong reaction to this particular kind of list.
Confirmed, Claimed and Unknown
Extortion groups exaggerate, because a bigger number puts more pressure on the victim. Companies minimise, because they have lawyers. The honest way to read any breach is to sort every statement into one of three columns and act on the first one while planning for the second.
| Confirmed | Claimed by the attackers | Not disclosed |
|---|---|---|
| A social engineering attack in July 2026. | 623GB taken in total. | The specific technique: phone call, help desk impersonation, a malicious app authorisation, or something else. |
| About 1.6 million unique email addresses, with names, phone numbers and physical addresses, verified by Have I Been Pwned. | A 280GB archive published, and that it represents part of a larger haul. | Which internal system held the data, and whether it was a RingCentral system or a third party platform RingCentral uses. |
| RingCentral says the core platform was not affected and services ran without disruption. | Anything the group says about what else is in the unpublished portion. | How many of the records relate to Australian businesses or individuals. Nothing published so far says. |
| RingCentral did not pay and engaged a forensic firm. | The final findings of that forensic investigation. |
Why we are careful about the entry method
A lot of commentary has assumed RingCentral was breached the same way as other ShinyHunters victims, through a voice phishing call that tricked an employee into approving access to a customer relationship management system. That is plausible given the group's history, and it may turn out to be right. It has not been confirmed, and we are not going to state it as fact. What matters for your defences is the same either way: the attack targeted people, not software, and the defences that work are the ones that do not rely on a person spotting a lie in real time.
The Campaign Behind It
RingCentral was not a one-off. The group operating under the ShinyHunters name has been responsible for one of the most sustained data theft campaigns of the last two years, and its method is consistent enough that it is worth understanding in some detail.
2025: the CRM wave. From mid 2025 the group phoned employees at large organisations, posed as internal IT support, and talked them through authorising what looked like a legitimate data export tool for their Salesforce environment. It was an attacker controlled application. Once approved, it had broad access to customer records and did not need a password or a second factor again, because the employee had granted it a standing token. Salesforce itself was not breached; its customers' staff were persuaded to open the door. Qantas was among the victims in July 2025, with data on around 5.7 million customers taken from a third party platform used by one of its contact centres. Google, Allianz Life and several luxury brands were hit the same way.
Late 2025 into 2026: the single sign-on wave. The method moved up a level. Callers posed as help desk staff, told employees their multi-factor authentication needed updating, and walked them onto convincing copies of their company's single sign-on page while the attacker relayed the login and the one-time code to the real site in real time. Security firms counted more than a hundred organisations targeted by January 2026. Okta published warnings about custom phishing kits built for exactly this. ADT confirmed a breach in April 2026 after an extortion demand from the group, and McKesson disclosed an incident involving voice phishing and stolen single sign-on credentials.
The common thread is that none of this required a software vulnerability. It required a phone, a plausible script, some research on the target, and a second factor that could be relayed. Every successful step depended on an employee believing a caller.
The most effective intrusion technique of 2025 and 2026 was a phone call. That is an uncomfortable fact for anyone who runs a phone system, and it is why a breach at a phone provider is worth more attention than its data classes suggest. The list that was stolen is the list of people this group, or anyone who buys the archive, will call next.
Why Contact Details Are Not Nothing
Here is what a single record in a leak like this typically gives an attacker, and what each field is used for.
| Field | What it lets an attacker do |
|---|---|
| Name | Open a call or email with the person's name, which immediately lifts trust. Search LinkedIn for their role and manager. |
| Work email | Target a phishing email precisely, and confirm the company's email format for everyone else there. |
| Phone number | Call or text directly. For a mobile, it is also the key to a SIM swap or port-out attempt. |
| Physical address | Answer "can you confirm your address" style security questions, and add credibility to an invoice or delivery pretext. |
| The fact they are a customer of this provider | The field nobody lists and the most valuable one. It tells the attacker exactly which company to impersonate. |
That last row is the point. A generic scam call claiming to be "your phone company" fails most of the time because most people know it is a guess. A call that says "this is RingCentral account security, we are contacting affected customers about the July incident, I can see your account is registered to Sarah at 14 Smith Street" is a completely different proposition. It is accurate, it refers to a real event the person may have read about, and it arrives with an apparently legitimate reason to ask for verification. Breach follow-up calls work precisely because the breach was real.
There is also a second-order effect. Once one leak is public, it gets combined with others. The Qantas data, the Optus and Medibank breaches from 2022, and years of smaller leaks already mean many Australians have their details circulating. Each new list adds a field or confirms a current one. The RingCentral data adds something few other leaks have: a verified link between a person and the platform that carries their business calls.
Five Attacks a Leaked List Enables
These are the five we would expect to see against anyone on the list, roughly in order of likelihood.
1. The provider impersonation call. "We are calling about the security incident. To protect your account we need to verify you and reset your admin access." The goal is either the admin login for your phone portal or a one-time code that lets the caller reset it. With admin access to a business phone system an attacker can forward your main number, read voicemail, pull call recordings, add users and run up call charges.
2. The help desk pretext against your staff. The attacker calls one of your employees posing as your IT provider or your phone provider, citing the breach as the reason, and walks them through "re-enrolling" their authenticator on a fake login page. This is the single sign-on technique described above, pointed at your business instead of at RingCentral.
3. The invoice or bank detail change. An email arrives from what appears to be your phone provider's billing team: following the incident, payment details have changed, please update. The address matches, the account name matches, the amount matches your usual bill. Payment redirection fraud is one of the most costly scams reported to Australian authorities for businesses, and a list of real customers with real addresses is exactly what makes it convincing.
4. The port-out or SIM swap. With a name, a mobile number and an address, an attacker can attempt to move a mobile number to a SIM they control. Australian mobile carriers have been required since 2020 to perform additional identity verification before a mobile number is ported, usually a one-time code sent to the existing service, which has cut this sharply. It has not eliminated it, because the verification step itself can be socially engineered: the victim is called and asked to read out the code "to confirm their identity". If the stolen number is the one that receives your banking or admin codes, a successful port gives the attacker all of them.
5. The data enrichment step nobody sees. Not every use is immediate. Many buyers of leaked data simply add it to larger datasets and use it months later. Expect the effect of this list to show up well into 2027, which is why a one-off reminder to staff is not enough.
If this sounds familiar, it is the same playbook we described in our guide to voice cloning and vishing, with one addition: the caller now has genuine data to anchor the lie. Synthetic voices make the call sound right. A breach list makes the details right.
If You Use RingCentral or Optus Loop
RingCentral has said it is contacting affected customers directly. That is the right thing to do, and it also creates a problem: the genuine notification and the fake follow-up will look similar. Some practical points.
Check exposure without clicking anything. Go directly to haveibeenpwned.com in a browser you trust and enter the email addresses your business uses with the provider, especially the admin and billing contacts. Do not use a link from any email about the breach, including ones that look genuine. If you manage a domain, Have I Been Pwned also offers domain level searches after you verify ownership.
Treat inbound contact about the incident as untrusted by default. If RingCentral or anyone claiming to be RingCentral calls, hang up and ring back through the number in your account portal or on your last invoice. A genuine provider will never object to this. A scammer always will, usually with urgency.
Optus Loop customers. Optus announced in March 2024 that RingCentral would power its cloud communications for Australian businesses, and many Optus Loop customers have been moved, or are being moved, to the RingCentral-built platform. Nothing published about this incident says Optus customers were among the affected records, and we are not suggesting they were. But if your business is mid-migration, you are already expecting calls and emails about account changes, logins and new portals from both companies, which is exactly the environment in which a fake one is hardest to spot. Be especially strict about verifying any request that arrives during the migration window. Our Optus Loop migration guide covers the change itself.
A fake breach notification is a known follow-up attack
After large breaches it is common to see waves of emails and texts pretending to be the breach notification, offering "identity protection" or "account verification" behind a link. If you receive any message about the RingCentral incident that asks you to click, log in, call a number in the message, or confirm details, treat it as hostile until you have verified it through a channel you already had before the message arrived.
Ten Things to Do This Week
These apply whether or not you are a RingCentral customer. Most take minutes. The first five are the ones that stop real losses.
| # | Action | Why |
|---|---|---|
| 1 | Write down a callback rule and tell everyone. Any request to change access, payment details or phone configuration is verified by calling back on a number you already hold. | This single rule defeats most of the five attacks above, because the attacker controls the inbound call and not your outbound one. |
| 2 | Move phone system admin accounts to phishing-resistant MFA: a passkey or a hardware security key. | Codes by SMS or authenticator app can be relayed by a live caller. Passkeys cannot, because they only work on the real site. |
| 3 | Ask your mobile carrier to add a port-out and SIM change lock to business mobiles, especially any that receive admin or banking codes. | It adds a step an attacker holding only a name, number and address cannot complete. |
| 4 | Confirm supplier bank details by phone before paying any invoice where the details changed. | Payment redirection is the most direct way a leaked customer list becomes cash. |
| 5 | Brief staff with the actual script they are likely to hear, not a generic warning. | People recognise a script they have heard before. They do not recognise "be alert to phishing". |
| 6 | Review who has admin rights on your phone system and remove anyone who no longer needs them. | Fewer admin accounts is fewer targets. |
| 7 | Check call forwarding rules on main numbers and key users for anything unexpected. | Silent forwarding to an attacker's number is a quiet way to intercept verification calls. |
| 8 | Turn on login alerts and audit logs in your phone portal if they are not already on. | You want to know about a new admin login the same day, not at the end of the month. |
| 9 | Check international calling and premium number barring are set the way you want. | Toll fraud is still how compromised phone accounts are most often monetised. |
| 10 | Check whether any personal information your business holds was in the exposed data, and if so, start a breach assessment. | The notification obligations may be yours as well as your provider's. See below. |
Controls That Actually Stop Vishing
Security awareness training is worth doing, but it is not a control. A person having a busy afternoon, speaking to a polite caller who knows their name and refers to a real news story, will get it wrong sometimes. The controls that work are the ones that still hold when somebody does.
Phishing-resistant MFA
Passkeys and FIDO2 hardware keys are tied to the genuine website address. If an employee is talked onto a fake login page, the key simply does not respond. This is the control that broke the relay technique used throughout the ShinyHunters single sign-on campaign.
Callback verification
Every sensitive request is confirmed on a number you already hold. It costs a minute and it moves control of the conversation from the attacker to you. Write it into policy so staff are never in the position of having to be rude.
App consent controls
Stop ordinary users from authorising new third party applications against your CRM, email or file storage without an administrator approving them. This is the exact step the 2025 Salesforce wave relied on.
Help desk identity rules
Whoever resets passwords or MFA, internal IT or an outsourced provider, needs a verification procedure that does not rely on information a breach could supply. Name, address and phone number all fail that test now.
The Australian Signals Directorate's Essential Eight has moved in the same direction, with phishing-resistant MFA expected at the higher maturity levels. For a small business the practical version is simple: every account that can change your phone system, your email, your banking or your domain should use a passkey or a hardware key, and nobody should be able to approve access for a new app on their own.
On the phone system itself, look for per-user and admin audit logs, alerts on new admin logins and forwarding changes, the ability to restrict admin access, and barring of international and premium destinations by default. Our older but still relevant guide to VoIP security and phone system fraud covers the toll fraud side in detail, and how AI improves business security covers what automated call screening can and cannot catch.
Questions to Ask Any Phone Provider
No provider can promise it will never be breached, and you should be wary of one that does. What you can assess is how they reduce the chance, limit the damage, and tell you when something goes wrong.
| Question | What a good answer sounds like |
|---|---|
| Where is my account and contact data held, and by whom? | A clear list of systems and countries, including third party platforms like CRM and support desks. Customer data leaks from support tools as often as from the core platform. |
| How do your support staff verify me before making changes? | Something beyond name, address and phone number, such as a PIN, a portal-initiated request, or a callback to a registered contact. |
| How would you contact me about an incident, and how do I verify it is you? | A defined channel, and a clear statement that they will never ask for passwords, codes or payment changes in a breach notice. |
| Does the admin portal support passkeys or hardware keys? | Yes, and the option to require them for all admins. |
| What audit logs and alerts can I see? | Logins, admin changes, forwarding changes and new devices, exportable, with alerts you can route to email. |
| How do you handle number port-out requests? | Authorisation checks against the account holder, notification to the registered contact, and a way to add a port lock. |
| Who can your staff reach, and from where? | Access to customer data restricted by role, logged, and ideally held and supported in Australia. |
| What happened last time? | A provider willing to talk plainly about past incidents and what changed is more trustworthy than one that says it has never had one. |
If you are comparing platforms at the moment, our comparison of RingCentral, 8x8 and Aircall alternatives looks at the commercial and support differences. We would add one thing to any comparison after this year: ask where the support tools and customer records live, not just where the calls are processed. The 2025 and 2026 campaigns went after customer records and the people who could reach them.
Your Own Privacy Act Obligations
Most businesses read a supplier's breach as the supplier's problem. Under Australian privacy law that is not always true.
The Notifiable Data Breaches scheme applies to organisations covered by the Privacy Act, which includes businesses with annual turnover above $3 million and some smaller ones, such as health service providers. If personal information you hold is involved in a breach that is likely to cause serious harm, and you cannot prevent that harm through remedial action, you must notify the affected individuals and the Office of the Australian Information Commissioner. If you only suspect a breach, you must take reasonable steps to assess it within 30 days.
For a provider incident like this one, the question to ask is whether any of the exposed data was personal information your business was responsible for, for example the details of your own staff or of customers held in an account with the provider. If it was, the provider's notification does not automatically discharge your obligation. In most supplier incidents the organisations involved coordinate so that a single notification goes out, but you need to confirm that is happening rather than assume it.
The small business exemption still exists, for now
As at writing, most businesses under the $3 million threshold are still exempt from the Privacy Act, although removal of the exemption has been agreed in principle by the government and remains on the reform agenda. Even exempt businesses carry reputational and contractual exposure if customer data they hold leaks, and many have contracts with larger clients that require breach notification regardless. From 10 December 2026, covered businesses also have new disclosure obligations about substantially automated decisions, covered in our automated decisions guide.
Two practical steps regardless of size. Keep a short record of what you checked and when, so that if a customer asks, or a regulator does, you can show you assessed it. And look at what personal information you actually keep in your phone system: call recordings, voicemail, transcripts, contact directories and SMS threads are personal information, and the less of it you hold beyond what you need, the less there is to lose. Our coverage of the Origin Energy breach earlier this year goes through the same obligations from a different angle.
Is Cloud Still the Safer Choice?
Some businesses will read this and wonder whether an office phone system in a cupboard would have been safer. For almost everyone the answer is no, and it is worth being precise about why.
The RingCentral incident did not involve the phone platform being compromised. It involved customer records, taken by persuading a person. An on-premises system does not remove that risk, because you still have a supplier with your account records and a support desk that can be phoned. What it does add is the set of risks that cloud providers largely remove: unpatched firmware exposed to the internet, default passwords, no audit logs, and toll fraud that runs all weekend because nobody is watching. Older on-premises systems are consistently among the most common sources of phone fraud losses for small businesses.
The better lesson is narrower. Security of a phone service now depends as much on the provider's people and support processes as on its network. Ask about both.
| Risk | Old on-premises PBX | Well run cloud platform |
|---|---|---|
| Social engineering of support staff | Present, through the installer or maintainer | Present, through the provider |
| Unpatched software exposed to the internet | Common | Patched centrally |
| Toll fraud through weak passwords | Common, often unnoticed for days | Monitored and barred by default on good platforms |
| Audit logs and login alerts | Rare | Standard |
| Phishing-resistant MFA on admin access | Usually impossible | Available on good platforms |
How We Approach This
We are a phone provider, so everything above applies to us too, and we would rather say that than pretend otherwise. What we can tell you is how we are set up.
Uniden Voice over Cloud is Australian owned, and your calls, recordings and account data are hosted in Australia and supported by an Australian team. Support staff verify account holders before making configuration changes, and requests to change admin access, forwarding or numbers are confirmed through registered contacts rather than on the strength of an inbound call. The admin portal keeps audit logs of logins and changes, and international and premium destinations can be barred by default. We will never ask you for a password, a one-time code or a change of bank details in a phone call or an incident notice, and if anyone claiming to be us does, hang up and ring 1300 881 662.
If you would like a second pair of eyes on your current setup, whoever it is with, we are happy to go through the checklist above with you: admin access, MFA, forwarding, barring, porting locks and what your provider holds about you. It usually takes half an hour and it is the most useful half hour most businesses will spend on phone security this year.