RingCentral A.I CyberSecurity Scoring
RingCentral
Company Information
Website:http://www.ringcentral.com
Employees number:6,706
Number of followers:318,188
NAICS:5112
Industry Type:Software Development
Homepage:ringcentral.com
RingCentral Risk Score (AI oriented)
Between 650 and 699
RingCentralSoftware Development
Updated:
13/08/2026
13/08/2026
673/1000
Weak
B
RingCentral Global Score (TPRM)
xxxx
RingCentralSoftware Development
Score locked

RingCentralWeak
Current Score
673B (WEAK)
01000
2 incidents
-46.5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
673
JULY 2026
691
Cyber Attack
28 Jul 2026 • RingCentral
RingCentral: Phishing service spoofs RingCentral to steal Microsoft 365 accounts
Greatness Phishing-as-a-Service Platform Expands to AiTM and Device-Code Attacks
672
CRITICAL-19
RIN1785882225
Greatness Phishing-as-a-Service Platform Expands to AiTM and Device-Code Attacks
The Greatness phishing-as-a-service (PhaaS) platform, active since mid-2022, has evolved from credential phishing to more sophisticated adversary-in-the-middle (AiTM) and device-code phishing attacks targeting Microsoft 365 accounts. Initially focused on Microsoft 365 users in the U.S., Canada, the UK, Australia, and South Africa, the platform now also targets iCloud, Yahoo, and Google Workspace. Cybercriminals can subscribe to Greatness for $289 per month via a Telegram channel with thousands of users.
In a recent campaign uncovered by email security firm ZeroBEC, Greatness operators exploited RingCentral a business communications platform to bypass email security filters. Attackers spoofed RingCentral’s domain (service@ringcentral[.]com), sending fake voicemail and performance-review notifications to legitimate users. Despite failing SPF, DMARC, and DKIM checks, the emails evaded detection because RingCentral was whitelisted, achieving a Spam Confidence Level (SCL) of -1 on Microsoft Exchange. A fraudulent "verified sender" banner further reduced suspicion.
Victims who clicked embedded links were redirected to Greatness infrastructure, where they faced either an AiTM phishing flow capturing MFA-approved authentication tokens or a device-code phishing attack. Post-compromise, attackers replayed stolen tokens from VPS and commercial VPNs to access Outlook mailboxes, Teams chats, SharePoint, OneDrive files, and other Microsoft 365 data, with persistence lasting over two weeks in some cases.
While RingCentral recently disclosed a data breach linked to the ShinyHunters threat actor, ZeroBEC notes that Greatness operators may have obtained target lists from this incident, though no direct connection has been confirmed. The attack highlights risks of overbroad safe-sender lists and underscores the need for stricter email authentication controls. Organizations are advised to audit whitelisted domains, monitor for Greatness infrastructure, and investigate suspicious MFA-approved logins from hosting or VPN sources.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JULY 2026
764
Breach
01 Jul 2026 • RingCentral
RingCentral: Have I Been Pwned’s Post
RingCentral Hit by ShinyHunters Extortion Attack, 1.6M Email Addresses Leaked
690
CRITICAL-74
RIN1786620488
RingCentral Hit by ShinyHunters Extortion Attack, 1.6M Email Addresses Leaked
Last month, cloud communications provider RingCentral fell victim to an extortion attack by the cybercriminal group ShinyHunters, which later published 1.6 million email addresses and other personal data allegedly stolen from the company.
The leaked data was cross-referenced with existing breaches, revealing that 44% of the exposed email addresses were already present in LinkedIn’s records and other third-party databases. The incident highlights the growing risk of credential reuse and the potential for further exploitation by threat actors.
ShinyHunters, known for targeting high-profile organizations, has previously been linked to breaches involving stolen databases sold or leaked on underground forums. The full scope of the compromised data beyond email addresses remains unclear, but the exposure underscores the persistent threat of extortion-driven cyberattacks in enterprise environments.
The breach was confirmed by security researcher Troy Hunt, who added the exposed emails to the Have I Been Pwned database, allowing users to check for potential exposure. No official statement from RingCentral regarding the attack’s impact or mitigation efforts has been released at this time.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JUNE 2026
764
MAY 2026
764
APRIL 2026
762
MARCH 2026
762
FEBRUARY 2026
762
JANUARY 2026
762
DECEMBER 2025
762
NOVEMBER 2025
762
OCTOBER 2025
762
SEPTEMBER 2025
762
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for RingCentral ??
What was RingCentral's A.I Rankiteo Cyber Score in July 2026 ??
What was RingCentral's A.I Rankiteo Cyber Score in June 2026 ??
What was RingCentral's A.I Rankiteo Cyber Score in May 2026 ??
What was RingCentral's A.I Rankiteo Cyber Score in April 2026 ??
What was RingCentral's A.I Rankiteo Cyber Score in March 2026 ??
What was RingCentral's A.I Rankiteo Cyber Score in February 2026 ??
What was RingCentral's A.I Rankiteo Cyber Score in January 2026 ??
What was RingCentral's A.I Rankiteo Cyber Score in December 2025 ??
What was RingCentral's A.I Rankiteo Cyber Score in November 2025 ??
What was RingCentral's A.I Rankiteo Cyber Score in October 2025 ??
What was RingCentral's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on RingCentral's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with RingCentral ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view RingCentral's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?