Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Phishing service spoofs RingCentral to steal Microsoft 365 accounts

0
High
Phishingphishing
Published: 08/04/2026 (08/04/2026, 21:45:36 UTC)
Source: Bleeping Computer

Description

The Greatness phishing-as-a-service (PhaaS) platform targets Microsoft 365 accounts using advanced phishing techniques including adversary-in-the-middle and device-code phishing. It spoofs RingCentral emails to bypass email security filters by exploiting whitelisting and safe-sender list trust. Post-compromise, attackers access Microsoft 365 data and services via stolen authentication tokens. The platform is sold to cybercriminals and has been active since at least mid-2022, targeting users in multiple countries. Researchers recommend auditing safe-sender lists and monitoring suspicious MFA-approved sign-ins.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/04/2026, 22:02:13 UTC

Technical Analysis

Greatness is a phishing-as-a-service platform that has evolved from credential phishing to sophisticated adversary-in-the-middle and device-code phishing attacks targeting Microsoft 365 accounts. It abuses the RingCentral communications platform by sending spoofed emails that bypass email filters due to RingCentral being whitelisted, despite failing SPF, DMARC, and lacking DKIM signatures. These emails lure victims with fake voicemail and performance-review notifications. Victims who interact with the phishing links are routed through Microsoft 365-specific phishing flows that capture MFA-approved authentication tokens. Attackers then use these tokens to access compromised accounts via VPS or VPN infrastructure, enumerating mailboxes, Teams, SharePoint, OneDrive, contacts, calendars, and applications through Microsoft Graph API. Access persistence of over two weeks has been observed. The platform is sold for $289/month on Telegram and targets users in the US, Canada, UK, Australia, and South Africa. The campaign likely leverages a RingCentral data breach to identify valid targets. Researchers advise reviewing safe-sender lists, removing blanket domain exclusions, hunting for Greatness infrastructure, and monitoring suspicious MFA sign-ins.

Potential Impact

Attackers gain unauthorized access to Microsoft 365 accounts by capturing MFA-approved authentication tokens through phishing flows. This access allows them to enumerate and exfiltrate sensitive data from Outlook, Teams, SharePoint, OneDrive, contacts, calendars, and registered applications. The compromise can persist for more than two weeks, enabling prolonged unauthorized data access and potential further exploitation within affected organizations.

Defensive Guidance

No official vendor patch applies as this is a phishing campaign. Recommended mitigations include auditing and tightening safe-sender lists to avoid blanket domain exclusions that allow spoofed emails to bypass filters. Organizations should hunt for Greatness infrastructure indicators and monitor for suspicious MFA-approved Microsoft 365 sign-ins originating from VPS or commercial VPN IP addresses. If compromise is suspected, administrators should revoke all access and refresh tokens, review OAuth consent grants, Microsoft Graph activity, and access permissions to Microsoft 365 services.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.79,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://www.bleepingcomputer.com/news/security/phishing-service-spoofs-ringcentral-to-steal-microsoft-365-accounts/","fetched":true,"fetchedAt":"2026-08-04T22:02:01.288Z","wordCount":816}

Threat ID: 6a726159bf8831d5398b164b

Added to database: 08/04/2026, 22:02:01 UTC

Last enriched: 08/04/2026, 22:02:13 UTC

Last updated: 08/05/2026, 03:38:57 UTC

Views: 8

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses