RingCentral: Phishing service spoofs RingCentral to steal Microsoft 365 accounts

RingCentral: Phishing service spoofs RingCentral to steal Microsoft 365 accounts

Greatness Phishing-as-a-Service Platform Expands to AiTM and Device-Code Attacks

The Greatness phishing-as-a-service (PhaaS) platform, active since mid-2022, has evolved from credential phishing to more sophisticated adversary-in-the-middle (AiTM) and device-code phishing attacks targeting Microsoft 365 accounts. Initially focused on Microsoft 365 users in the U.S., Canada, the UK, Australia, and South Africa, the platform now also targets iCloud, Yahoo, and Google Workspace. Cybercriminals can subscribe to Greatness for $289 per month via a Telegram channel with thousands of users.

In a recent campaign uncovered by email security firm ZeroBEC, Greatness operators exploited RingCentral a business communications platform to bypass email security filters. Attackers spoofed RingCentral’s domain (service@ringcentral[.]com), sending fake voicemail and performance-review notifications to legitimate users. Despite failing SPF, DMARC, and DKIM checks, the emails evaded detection because RingCentral was whitelisted, achieving a Spam Confidence Level (SCL) of -1 on Microsoft Exchange. A fraudulent "verified sender" banner further reduced suspicion.

Victims who clicked embedded links were redirected to Greatness infrastructure, where they faced either an AiTM phishing flow capturing MFA-approved authentication tokens or a device-code phishing attack. Post-compromise, attackers replayed stolen tokens from VPS and commercial VPNs to access Outlook mailboxes, Teams chats, SharePoint, OneDrive files, and other Microsoft 365 data, with persistence lasting over two weeks in some cases.

While RingCentral recently disclosed a data breach linked to the ShinyHunters threat actor, ZeroBEC notes that Greatness operators may have obtained target lists from this incident, though no direct connection has been confirmed. The attack highlights risks of overbroad safe-sender lists and underscores the need for stricter email authentication controls. Organizations are advised to audit whitelisted domains, monitor for Greatness infrastructure, and investigate suspicious MFA-approved logins from hosting or VPN sources.

Source: https://www.bleepingcomputer.com/news/security/phishing-service-spoofs-ringcentral-to-steal-microsoft-365-accounts/

RingCentral cybersecurity rating report: https://www.rankiteo.com/company/ringcentral

"id": "RIN1785882225",
"linkid": "ringcentral",
"type": "Cyber Attack",
"date": "7/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Legitimate users of RingCentral '
                                              'and Microsoft 365',
                        'industry': 'Technology, Communications',
                        'name': 'RingCentral',
                        'type': 'Business communications platform'},
                       {'location': 'U.S., Canada, UK, Australia, South Africa',
                        'type': 'Organizations using Microsoft 365, iCloud, '
                                'Yahoo, Google Workspace'}],
 'attack_vector': 'Email spoofing, malicious links, token replay',
 'data_breach': {'data_exfiltration': 'Possible (attackers accessed and '
                                      'persisted in systems for over two '
                                      'weeks)',
                 'personally_identifiable_information': 'Likely (MFA tokens, '
                                                        'email communications, '
                                                        'business data)',
                 'sensitivity_of_data': 'High (personally identifiable '
                                        'information, business communications, '
                                        'sensitive documents)',
                 'type_of_data_compromised': 'Authentication tokens, Outlook '
                                             'mailboxes, Teams chats, '
                                             'SharePoint, OneDrive files, '
                                             'Microsoft 365 data'},
 'description': 'The Greatness phishing-as-a-service (PhaaS) platform, active '
                'since mid-2022, has evolved from credential phishing to more '
                'sophisticated adversary-in-the-middle (AiTM) and device-code '
                'phishing attacks targeting Microsoft 365 accounts. Initially '
                'focused on Microsoft 365 users in the U.S., Canada, the UK, '
                'Australia, and South Africa, the platform now also targets '
                'iCloud, Yahoo, and Google Workspace. Cybercriminals can '
                'subscribe to Greatness for $289 per month via a Telegram '
                'channel with thousands of users. In a recent campaign, '
                'Greatness operators exploited RingCentral to bypass email '
                'security filters by spoofing its domain, sending fake '
                'voicemail and performance-review notifications. Victims were '
                'redirected to Greatness infrastructure, where they faced AiTM '
                'or device-code phishing attacks. Post-compromise, attackers '
                'accessed Outlook mailboxes, Teams chats, SharePoint, OneDrive '
                'files, and other Microsoft 365 data, with persistence lasting '
                'over two weeks in some cases.',
 'impact': {'brand_reputation_impact': 'Potential reputational damage due to '
                                       'phishing attacks and data breaches',
            'data_compromised': 'Outlook mailboxes, Teams chats, SharePoint, '
                                'OneDrive files, Microsoft 365 data',
            'identity_theft_risk': 'High (MFA-approved tokens and sensitive '
                                   'data compromised)',
            'operational_impact': 'Unauthorized access to business '
                                  'communications and sensitive data, '
                                  'potential data exfiltration',
            'systems_affected': 'Microsoft 365 (Outlook, Teams, SharePoint, '
                                'OneDrive), iCloud, Yahoo, Google Workspace'},
 'initial_access_broker': {'backdoors_established': 'MFA-approved '
                                                    'authentication tokens, '
                                                    'persistence in Microsoft '
                                                    '365 accounts',
                           'entry_point': 'Email spoofing (RingCentral '
                                          'domain), malicious links',
                           'high_value_targets': 'Microsoft 365 users, '
                                                 'business communications '
                                                 'data'},
 'lessons_learned': 'Risks of overbroad safe-sender lists, need for stricter '
                    'email authentication controls, importance of monitoring '
                    'for suspicious MFA-approved logins from hosting or VPN '
                    'sources',
 'motivation': 'Financial gain, data exfiltration, unauthorized access to '
               'sensitive information',
 'post_incident_analysis': {'corrective_actions': 'Audit and restrict '
                                                  'whitelisted domains, '
                                                  'enforce strict email '
                                                  'authentication, monitor for '
                                                  'suspicious MFA logins, '
                                                  'educate users on phishing '
                                                  'risks',
                            'root_causes': 'Lack of strict email '
                                           'authentication, whitelisted '
                                           'domains, MFA bypass via token '
                                           'replay, exploitation of trusted '
                                           'business communications platforms'},
 'recommendations': 'Audit whitelisted domains, monitor for Greatness '
                    'infrastructure, investigate suspicious MFA-approved '
                    'logins, enforce strict email authentication (SPF, DMARC, '
                    'DKIM)',
 'references': [{'source': 'ZeroBEC'},
                {'source': 'RingCentral data breach disclosure'}],
 'response': {'enhanced_monitoring': 'Monitoring for Greatness infrastructure '
                                     'and suspicious MFA-approved logins from '
                                     'hosting or VPN sources',
              'third_party_assistance': 'ZeroBEC (email security firm)'},
 'threat_actor': 'Greatness Phishing-as-a-Service (PhaaS) operators',
 'title': 'Greatness Phishing-as-a-Service Platform Expands to AiTM and '
          'Device-Code Attacks',
 'type': 'Phishing, Adversary-in-the-Middle (AiTM), Device-Code Phishing',
 'vulnerability_exploited': 'Lack of strict email authentication (SPF, DMARC, '
                            'DKIM), whitelisted domains, MFA bypass via token '
                            'replay'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.