Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Microsoft Tells Engineers ‘Tokenmaxxing Is Not What We Are Optimizing For’

    August 4, 2026

    NCSC statement in response to recent incidents resulting from frontier AI evaluations

    August 4, 2026

    Phishing service spoofs RingCentral to steal Microsoft 365 accounts

    August 4, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»Phishing service spoofs RingCentral to steal Microsoft 365 accounts
    News

    Phishing service spoofs RingCentral to steal Microsoft 365 accounts

    adminBy adminAugust 4, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Phishing service spoofs RingCentral to steal Microsoft 365 accounts

    The Greatness phishing-as-a-service (PhaaS) platform has expanded from credential phishing to adversary-in-the-middle attacks and device-code phishing targeting Microsoft 365 accounts.

    The platform has been active since at least mid-2022, targeting Microsoft 365 users in the United States, Canada, the UK, Australia, and South Africa.

    It evolved over the years and now targets multiple platforms, including Microsoft 365, iCloud, Yahoo, and Google Workspace.

    image

    Currently, it is sold for $289 per month to cybercriminals over a Telegram channel with thousands of subscribers.

    The Greatness panel
    The Greatness panel
    Source: ZeroBEC

    In a recent campaign observed by researchers at email security company ZeroBEC, Greatness operators abused the RingCentral communications platform to bypass email security filters on the recipient side.

    RingCentral is a communications platform used by businesses for services such as cloud calling, messaging, and voicemail.

    In the Greatness phishing activity, the attacker impersonated the platform by claiming their emails came from service@ringcentral[.]com, targeting actual users of the service.

    These emails used fake voicemail and performance-review notifications as lures to entice recipients to open them.

    Although the messages originated from an unknown IONOS mail server, failed SPF and DMARC checks, and had no DKIM signature, they were still accepted by the receiving systems because RingCentral was whitelisted.

    Moreover, the emails included a fraudulent banner claiming that the sender had been verified by the organization’s safe-sender list, which helped reduce suspicion at the human level.

    Sample email spoofing RingCentral
    Sample email spoofing RingCentral
    Source: ZeroBEC

    ZeroBEC explains that the tactic achieved a Spam Confidence Level (SCL) of -1 on Microsoft Exchange, allowing them to bypass the normal email filtering stages.

    Clicking the button embedded in those emails took victims to the Greatness infrastructure, where they were routed either through a Microsoft adversary-in-the-middle (AiTM) phishing flow that captured an MFA-approved authentication token or through a device-code phishing flow.

    Microsoft 365 phishing page with tenant-specific branding
    Microsoft 365 phishing page with tenant-specific branding
    Source: ZeroBEC

    Post-compromise, the attacker replayed Microsoft 365 authentication tokens from VPS and commercial VPN infrastructure to access the compromised accounts.

    They then enumerated Outlook mailboxes, Teams conversations, SharePoint sites, OneDrive files, contacts, calendars, and registered applications through Microsoft Graph, with access persisting for more than two weeks in some cases.

    It should be noted that RingCentral recently disclosed a data breach incident which was claimed by threat actor ShinyHunters.

    “This incident has affected data for a limited portion of RingCentral customers, and we are communicating with affected customers directly,” explained the company in a security bulletin published July 28.

    ZeroBEC comments that it’s likely that cybercriminals using Greatness got a list of valid targets, users of the RingCentral platform, from that incident, though a connection cannot be confidently made.

    The researchers recommend auditing safe-sender lists and replacing blanket domain exclusions with rules requiring valid email authentication.

    Also, hunt for Greatness infrastructure and suspicious MFA-approved Microsoft 365 sign-ins from hosting or VPN addresses.

    If compromise is suspected, administrators should revoke all access and refresh tokens, review OAuth consent, Microsoft Graph activity, and access to Microsoft 365 services.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleNew XCSSET variant targets macOS devs via compromised Xcode projects
    Next Article NCSC statement in response to recent incidents resulting from frontier AI evaluations
    admin
    • Website

    Related Posts

    News

    Microsoft Tells Engineers ‘Tokenmaxxing Is Not What We Are Optimizing For’

    August 4, 2026
    News

    NCSC statement in response to recent incidents resulting from frontier AI evaluations

    August 4, 2026
    News

    New XCSSET variant targets macOS devs via compromised Xcode projects

    August 4, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202677 Views

    IP Address Investigations and Local OSINT

    March 20, 202639 Views

    The Canadian Password Playbook: Navigating Compliance and Building Strong Passwords

    March 25, 202635 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202677 Views

    IP Address Investigations and Local OSINT

    March 20, 202639 Views

    The Canadian Password Playbook: Navigating Compliance and Building Strong Passwords

    March 25, 202635 Views
    Our Picks

    Microsoft Tells Engineers ‘Tokenmaxxing Is Not What We Are Optimizing For’

    August 4, 2026

    NCSC statement in response to recent incidents resulting from frontier AI evaluations

    August 4, 2026

    Phishing service spoofs RingCentral to steal Microsoft 365 accounts

    August 4, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.