AIWAS
ServicesPricingKnowledge BaseBlogGet Started
Email Us At
Get Started
Home » Alerts & Business  »  RingCentral data breach: 1.6 million contacts leaked, and what business owners should do
Attackers published 1.6 million email addresses, names, phone numbers and home addresses from the business phone service RingCentral. Here is why that makes a fake invoice look real, and the one rule that stops it.

RingCentral data breach: 1.6 million contacts leaked, and what business owners should do

A business phone service lost its customer list, and that list is now public. If your company uses RingCentral — or if you simply deal with suppliers who do — the practical risk to you is not a hacked phone line. It is an invoice that looks completely real.

What actually happened

RingCentral is a cloud-based business communications platform: phone, video and messaging that companies rent instead of running their own phone system. In July 2026 it was the target of what Have I Been Pwned describes as a "pay or leak" extortion campaign — attackers take a copy of a company's data, demand money to keep quiet, and publish it when they are not paid.

They were not paid. The data was published.

Have I Been Pwned is the breach index run by security researcher Troy Hunt; it catalogs confirmed breaches so that ordinary people can check whether their own details are in one. Its entry for RingCentral, added on August 13, 2026, records:

  • 1,596,490 unique email addresses — about 1.6 million
  • Names
  • Phone numbers
  • Physical addresses

In its own disclosure notice, RingCentral said the incident affected "a limited portion of RingCentral customers" and that it was contacting those affected directly. The company has not published a figure of its own, so the 1.6 million number is Have I Been Pwned's count of the published data, not a number RingCentral has confirmed.

Notice what is not on that list: no passwords, no card numbers, no bank details. That is exactly why a lot of business owners will read the headline and move on. That would be the wrong call, and the next section explains why.

Why a contact list is more dangerous than a password list

When passwords leak, the fix is mechanical. You change the password, you turn on two-factor authentication, and the stolen copy becomes worthless. It is annoying, but it ends.

A contact list never expires. Your name does not change. Your work email does not change. Your office address does not change. And the single most valuable fact in this particular breach is not in any of the four fields at all — it is the fact of being on the list. Every person in that file is now known to be a customer of a specific business phone service.

That is the ingredient scams have always been short of: context. A scam email fails because it is generic. It succeeds when it knows something true about you.

What the fraud actually looks like

Put yourself on the receiving end. You are the person in a small company who pays the bills — maybe the owner, maybe an office manager, maybe a bookkeeper who comes in two days a week.

An email arrives. It uses your real name. It refers to your business phone service by name, because the sender knows you use one. It attaches an invoice for a renewal, or it says a payment failed, or it says the supplier has changed banks and here are the new details. The phone number in the signature is real-looking. The postal address at the bottom is your actual address, which makes the whole thing feel administrative rather than suspicious.

Nothing in that email needs to be technically clever. There is no virus, no hacking, no software flaw. It is a normal email that asks a busy person to do a normal thing: pay an invoice, or update a supplier's bank details.

This is usually called business email compromise or invoice fraud, and it is worth being blunt about the shape of the risk. A phishing email that steals a password gives an attacker a login. A successful fake invoice moves your money out of your account, in one payment, to an account you authorized. Banks are far less able to reverse the second than to help with the first.

The person who pays your invoices is not careless. They are busy. A convincing fake only has to work once.

What to do this week

None of this requires a security team, new software, or a budget. It requires about half an hour.

  • Check your exposure. Put your work email address into haveibeenpwned.com. It is free, it takes ten seconds, and it will tell you every cataloged breach your address appears in — this one and any others.
  • Make one rule for bank detail changes. If any email asks you to change where a supplier's money goes, someone phones that supplier to confirm it — on a number you already had on file, never a number taken from the email. Write the rule down. This one rule is what breaks the attack, because the whole scam depends on the request never being checked through a second channel.
  • Tell whoever actually pays. The rule only works if the person holding the card or the bank login knows it exists. If that is a part-time bookkeeper or an outsourced accountant, tell them too.
  • Set a payment threshold that needs two people. Pick a number that would hurt to lose — for many small firms that is a few thousand — and require a second person to approve anything above it. Fraud that has to convince two people usually fails.
  • Treat urgency as the warning sign. "Pay today or service stops" is the most common lever in these emails, because pressure is what stops people checking. Real suppliers cope with a phone call.
  • If you use RingCentral, turn on multi-factor authentication anyway. No passwords were published in this breach, but attackers who know you are a customer will try to phish the login, and multi-factor authentication is what makes a stolen password insufficient on its own.

If you think you have already paid one

Speed is the only thing that matters. Call your bank immediately and ask them to attempt a recall — funds are sometimes recoverable in the first hours, rarely after that. Then call the real supplier on a known number to confirm the payment was fake, and report it to your national fraud or cybercrime reporting line. Keep the original email; do not delete it.

The part nobody likes

You did not do anything wrong here, and you could not have prevented it. Your details were held by a company you pay, that company was attacked, and the data was published. Every business has dozens of these relationships — the phone system, the accounting software, the CRM, the payroll provider, the online store. Each one holds a copy of who you are, and you control the security of none of them.

So the realistic goal is not to keep your details secret. That ship sails a little further every year. The goal is to make sure that knowing a lot about your business is not enough, on its own, to move your money. That is a process decision, not a technology purchase, and it is entirely within your control.

AI is going to make the fake emails better — cleaner writing, fewer tells, better targeting, at a scale that used to take a person. The defense does not change, and that is the encouraging part: a phone call to a number you already had works just as well against a perfect forgery as against a clumsy one.


We break down AI and security news for business owners — plain language, no jargon. More explainers in the AIWAS knowledge base, and short briefings on X at @AIWASai.

Primary source: Have I Been Pwned — RingCentral data breach, added August 13, 2026.

Leave a Reply

Your email address will not be published. Required fields are marked *