RingCentral Leak Creates a Phishing List

RingCentral said a July social-engineering breach led to the publication of names, addresses, email addresses, and phone numbers for about 1.6 million people. The company said affected customers were notified and that its core platform stayed online without disruption. The exposed data is useful because it combines real identities with contact points, which makes fraudulent messages and calls look specific and believable instead of generic spam. That gives attackers a ready-made pool for phishing, vishing, and extortion against the people named in the leak and anyone who trusts those contacts. For organizations that store customer or employee records in SaaS communications tools, the exposure can extend past RingCentral itself: a contact dump can become a targeting list for follow-on fraud even when the service keeps working.

Part of the PlainSec briefing for 2026-08-17

Editions

Sources