On 27 July, the extortion group ShinyHunters posted RingCentral, Inc. to its dark web leak site, claiming to have exfiltrated data and setting a 30 July deadline before publishing it. RingCentral is one of the most widely used cloud business phone and unified communications platforms, including among UK SMEs who’ve moved off traditional phone lines. Whether or not you use RingCentral specifically, the pattern here is the one worth paying attention to: ShinyHunters has built its entire 2026 playbook around going after third-party platforms and supply-chain weak points rather than breaking into individual companies directly, and this is far from its first high-profile target this year.
Why this isn’t “just a vendor’s problem”
The instinct when a supplier gets breached is to wait and see if you get a notification email. That’s the wrong order of operations. If you or your team use RingCentral — or any cloud communications, CRM, or collaboration tool — for anything involving customer names, numbers, call recordings, or account details, that data may now be sitting on a criminal’s timeline whether or not RingCentral confirms a breach publicly in the next few days. Ransomware groups running leak-site extortion campaigns like this one routinely follow through on “or we publish” threats, and stolen contact data gets recycled fast into targeted phishing and vishing (voice phishing) campaigns against exactly the customers and staff named in it.
What to do this week
Start with an honest audit, not a panic response. List every third-party SaaS tool your business depends on that touches customer or financial data — phone systems, CRM, invoicing, email marketing, helpdesk software — and check two things for each: do you know their current security status, and do you have a documented process for what happens if one of them is breached? Most SMEs can name their tools instantly but have never actually war-gamed a supplier breach. If RingCentral is one of your tools, watch for official communication directly from them (not from an email claiming to be them — verify via the app or your account rep), rotate any shared credentials or API keys connected to the account, and brief your team that a fresh wave of phishing calls or texts referencing real customer details is a realistic near-term risk, not a hypothetical one.
This is also a good prompt to check your own incident response plan exists in writing, because a supplier breach can trigger UK GDPR notification obligations for you too if customer data is involved, even though the breach itself happened on someone else’s system. If you don’t have a documented plan for third-party breach scenarios, KeepSafe monitors for exactly this kind of exposure and can help you build a response process before you need one under pressure.
The wider lesson on vendor concentration
The bigger strategic question this raises for growing SMEs is how much of your operational data sits with a small number of large platforms, and whether you’d know quickly if one of them was compromised. You don’t need to avoid cloud tools — the efficiency gains are real and mostly outweigh the risk — but you do need visibility. Ask new vendors directly about their breach notification commitments before you sign up, and revisit that question annually for the tools you already rely on, because the security posture of a platform you signed up with two years ago isn’t guaranteed to be the same today.
The takeaway
If you use RingCentral, check for official breach communications this week and treat any unexpected calls or texts referencing your account as suspicious until proven otherwise. If you don’t, use this as the trigger to actually write down which of your SaaS tools would hurt most if they appeared on a leak site next — and what you’d do about it.