Phishing service spoofs RingCentral to steal Microsoft 365 accounts
The Greatness phishing-as-a-service (PhaaS) platform targets Microsoft 365 accounts using advanced phishing techniques including adversary-in-the-middle and device-code phishing. It spoofs RingCentral emails to bypass email security filters by exploiting whitelisting and safe-sender list trust. Post-compromise, attackers access Microsoft 365 data and services via stolen authentication tokens. The platform is sold to cybercriminals and has been active since at least mid-2022, targeting users in multiple countries. Researchers recommend auditing safe-sender lists and monitoring suspicious MFA-approved sign-ins.
AI Analysis
Technical Summary
Greatness is a phishing-as-a-service platform that has evolved from credential phishing to sophisticated adversary-in-the-middle and device-code phishing attacks targeting Microsoft 365 accounts. It abuses the RingCentral communications platform by sending spoofed emails that bypass email filters due to RingCentral being whitelisted, despite failing SPF, DMARC, and lacking DKIM signatures. These emails lure victims with fake voicemail and performance-review notifications. Victims who interact with the phishing links are routed through Microsoft 365-specific phishing flows that capture MFA-approved authentication tokens. Attackers then use these tokens to access compromised accounts via VPS or VPN infrastructure, enumerating mailboxes, Teams, SharePoint, OneDrive, contacts, calendars, and applications through Microsoft Graph API. Access persistence of over two weeks has been observed. The platform is sold for $289/month on Telegram and targets users in the US, Canada, UK, Australia, and South Africa. The campaign likely leverages a RingCentral data breach to identify valid targets. Researchers advise reviewing safe-sender lists, removing blanket domain exclusions, hunting for Greatness infrastructure, and monitoring suspicious MFA sign-ins.
Potential Impact
Attackers gain unauthorized access to Microsoft 365 accounts by capturing MFA-approved authentication tokens through phishing flows. This access allows them to enumerate and exfiltrate sensitive data from Outlook, Teams, SharePoint, OneDrive, contacts, calendars, and registered applications. The compromise can persist for more than two weeks, enabling prolonged unauthorized data access and potential further exploitation within affected organizations.
Mitigation Recommendations
No official vendor patch applies as this is a phishing campaign. Recommended mitigations include auditing and tightening safe-sender lists to avoid blanket domain exclusions that allow spoofed emails to bypass filters. Organizations should hunt for Greatness infrastructure indicators and monitor for suspicious MFA-approved Microsoft 365 sign-ins originating from VPS or commercial VPN IP addresses. If compromise is suspected, administrators should revoke all access and refresh tokens, review OAuth consent grants, Microsoft Graph activity, and access permissions to Microsoft 365 services.
Affected Countries
United States, Canada, United Kingdom, Australia, South Africa
Phishing service spoofs RingCentral to steal Microsoft 365 accounts
Description
The Greatness phishing-as-a-service (PhaaS) platform targets Microsoft 365 accounts using advanced phishing techniques including adversary-in-the-middle and device-code phishing. It spoofs RingCentral emails to bypass email security filters by exploiting whitelisting and safe-sender list trust. Post-compromise, attackers access Microsoft 365 data and services via stolen authentication tokens. The platform is sold to cybercriminals and has been active since at least mid-2022, targeting users in multiple countries. Researchers recommend auditing safe-sender lists and monitoring suspicious MFA-approved sign-ins.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Greatness is a phishing-as-a-service platform that has evolved from credential phishing to sophisticated adversary-in-the-middle and device-code phishing attacks targeting Microsoft 365 accounts. It abuses the RingCentral communications platform by sending spoofed emails that bypass email filters due to RingCentral being whitelisted, despite failing SPF, DMARC, and lacking DKIM signatures. These emails lure victims with fake voicemail and performance-review notifications. Victims who interact with the phishing links are routed through Microsoft 365-specific phishing flows that capture MFA-approved authentication tokens. Attackers then use these tokens to access compromised accounts via VPS or VPN infrastructure, enumerating mailboxes, Teams, SharePoint, OneDrive, contacts, calendars, and applications through Microsoft Graph API. Access persistence of over two weeks has been observed. The platform is sold for $289/month on Telegram and targets users in the US, Canada, UK, Australia, and South Africa. The campaign likely leverages a RingCentral data breach to identify valid targets. Researchers advise reviewing safe-sender lists, removing blanket domain exclusions, hunting for Greatness infrastructure, and monitoring suspicious MFA sign-ins.
Potential Impact
Attackers gain unauthorized access to Microsoft 365 accounts by capturing MFA-approved authentication tokens through phishing flows. This access allows them to enumerate and exfiltrate sensitive data from Outlook, Teams, SharePoint, OneDrive, contacts, calendars, and registered applications. The compromise can persist for more than two weeks, enabling prolonged unauthorized data access and potential further exploitation within affected organizations.
Defensive Guidance
No official vendor patch applies as this is a phishing campaign. Recommended mitigations include auditing and tightening safe-sender lists to avoid blanket domain exclusions that allow spoofed emails to bypass filters. Organizations should hunt for Greatness infrastructure indicators and monitor for suspicious MFA-approved Microsoft 365 sign-ins originating from VPS or commercial VPN IP addresses. If compromise is suspected, administrators should revoke all access and refresh tokens, review OAuth consent grants, Microsoft Graph activity, and access permissions to Microsoft 365 services.
Affected Countries
Technical Details
- Classification
- {"confidence":0.79,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/phishing-service-spoofs-ringcentral-to-steal-microsoft-365-accounts/","fetched":true,"fetchedAt":"2026-08-04T22:02:01.288Z","wordCount":816}
Threat ID: 6a726159bf8831d5398b164b
Added to database: 08/04/2026, 22:02:01 UTC
Last enriched: 08/04/2026, 22:02:13 UTC
Last updated: 08/05/2026, 03:38:57 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.