RingCentral Got Breached. Your Phone System Has More Data Than You Think.

ShinyHunters stole 1.6 million records from RingCentral using social engineering. Your business phone system stores more sensitive data than most firms realize.

RingCentral disclosed a breach on July 28. The ShinyHunters extortion group got in through what the company called a “sophisticated social engineering campaign,” stole 623GB of data covering 1.6 million accounts, and demanded a ransom. RingCentral refused to pay. ShinyHunters published the data.

The stolen records include names, email addresses, phone numbers, and physical addresses. Have I Been Pwned confirmed the data is real after analyzing the leaked archive.

If your reaction is “we don’t use RingCentral, so this doesn’t apply to us,” keep reading. The breach is interesting not because of the specific platform, but because of what it reveals about how much data lives in your phone system.

Your phone system is a data store

Most firms treat their phone system as infrastructure, like electricity or internet. It’s there, it works, nobody thinks about what it contains. But modern cloud phone platforms are databases.

Your phone system probably stores:

Call logs and metadata. Every call your firm makes or receives is logged with timestamps, durations, and the numbers involved. For a law firm, that’s a record of every client communication, every opposing counsel conversation, every call to a court clerk. For a CPA firm, it’s a trail of every client you spoke with during tax season and exactly when.

Voicemails. Some are routine. Some contain privileged information, confidential financial data, or details about active matters. A client leaving a voicemail about their pending litigation or tax dispute is creating a record that sits on your phone provider’s servers, often indefinitely.

Contact directories. Your firm’s contact list, synced to the phone system, may include client names, personal phone numbers, email addresses, and notes. If your platform integrates with your CRM or practice management software, the contact records could include case numbers, matter descriptions, or billing information.

Text messages. If your platform supports SMS or team messaging (most do now), those conversations are stored. Staff discussing client matters over the platform’s messaging feature are creating records that exist outside your document management system.

Call recordings. If your firm records calls for training, quality, or compliance purposes, those recordings live on your provider’s infrastructure. A single recording of a client call could contain enough information to trigger notification obligations if it’s exposed.

Why the attack vector matters

ShinyHunters got into RingCentral through social engineering, not a software vulnerability. They convinced someone to give them access. No zero-day, no technical exploit, just a convincing enough pretext to get past a human.

This is the same attack pattern we covered when Teams vishing attacks impersonated IT support and when callback phishing campaigns targeted law firms. The consistent thread: attackers are getting through humans, not firewalls.

ShinyHunters specifically has been on a tear. Beyond RingCentral, they’ve claimed breaches at hundreds of Salesforce customers, multiple Snowflake customers, and the EY breach we covered two weeks ago. Their playbook targets cloud platforms and third-party integrations because one successful breach yields data from thousands of customer organizations.

What to evaluate at your firm

Start with what your provider stores and for how long. Check your data retention settings. Many platforms default to keeping call logs, voicemails, and recordings indefinitely. If you don’t need 18 months of voicemails sitting on their servers, adjust the retention period. Data that doesn’t exist can’t be stolen.

Then check who has admin access to the platform. Your phone system’s admin portal lets you access call logs, listen to voicemails, download recordings, and export contact lists. How many people have that access? Are former employees or former IT staff still listed as administrators? The same access hygiene that applies to email and file shares applies to your phone system.

After the RingCentral breach, it’s also worth verifying that MFA is enabled on your phone platform. Log into your provider’s admin portal and confirm that MFA is required for admin accounts at minimum, ideally for all user accounts. If your provider doesn’t support MFA on admin accounts, that’s a vendor risk conversation.

Check whether your phone system is on your vendor inventory. Cyber insurance applications increasingly ask for a list of vendors with access to sensitive data. Your phone provider has call metadata, voicemails, and potentially recordings. If they’re not on your vendor list, they should be.

And the simplest check: listen to your current voicemails. If any contain client names, case details, financial information, or confidential matters, you’re already storing sensitive data in a system that might not have the same protections as your document management platform.

The bigger picture

The last few months have produced a clear pattern. ShinyHunters hitting EY through a ticketing platform. The Azure tenant scraping campaign stealing 3.6 million records through compromised credentials. Now RingCentral through social engineering. The targets keep shifting to systems that organizations don’t think of as security-critical.

Every cloud service your firm uses is a potential breach vector. Email gets the most security attention because everyone recognizes it as a target. File shares get attention because that’s where documents live. But phone systems, ticketing platforms, scheduling tools, CRM platforms, and dozens of other “utility” services all contain data that would require notification if exposed.

The firms that handle this well aren’t the ones with the biggest security budgets. They’re the ones that actually know what data sits in each of their platforms and have thought about what happens if one of those platforms gets breached.


If you’re not sure what data your phone system stores or how long it keeps it, we can help you review your vendor security posture.