Phishing service spoofs RingCentral to steal Microsoft 365 accounts

A sophisticated phishing service has been exploiting a weakness in email security filters to steal Microsoft 365 account credentials. The Greatness platform, which has been active since at least mid-2022, has evolved from simple credential phishing to more complex attacks that target multiple platforms, including Microsoft 365, iCloud, Yahoo, and Google Workspace.

At the heart of this operation is a tactic known as adversary-in-the-middle (AiTM) phishing. Researchers at email security company ZeroBEC observed a recent campaign where Greatness operators used the RingCentral communications platform to bypass email filters. By impersonating the platform, claiming their emails came from service@ringcentral[.]com, they enticed actual users of the service to open malicious messages.

These lures were cleverly designed to look legitimate, using fake voicemail and performance-review notifications to trick recipients into opening them. What’s more, the emails included a fraudulent banner claiming that the sender had been verified by RingCentral’s safe-sender list, which helped reduce suspicion at the human level. This tactic achieved a Spam Confidence Level (SCL) of -1 on Microsoft Exchange, allowing them to bypass normal email filtering stages.

When victims clicked on the embedded button in these emails, they were routed through Greatness’ infrastructure, where they were either captured by an AiTM phishing flow that stole an MFA-approved authentication token or directed towards a device-code phishing flow. Post-compromise, attackers replayed Microsoft 365 authentication tokens from virtual private servers (VPS) and commercial VPN infrastructure to access the compromised accounts.

The researchers noted that this attack took advantage of RingCentral’s whitelisting policy, which allowed emails from unknown IONOS mail servers to be accepted by receiving systems despite failed SPF and DMARC checks. This highlights a critical vulnerability in email security filters, where whitelisting can inadvertently create an opening for attackers to exploit.

It’s worth noting that this incident may have been facilitated by a recent data breach at RingCentral, which was claimed by the threat actor ShinyHunters. While no direct connection has been made between Greatness and the breach, it’s possible that cybercriminals using Greatness obtained a list of valid targets from the incident.

To protect against such attacks, security teams must be vigilant in auditing safe-sender lists and replacing blanket domain exclusions with rules requiring valid email authentication. Additionally, they should hunt for Greatness infrastructure and suspicious MFA-approved Microsoft 365 sign-ins from hosting or VPN addresses.

If compromise is suspected, administrators should immediately revoke all access and refresh tokens, review OAuth consent, Microsoft Graph activity, and access to Microsoft 365 services. This emphasizes the importance of staying proactive in security, regularly testing email filters and detecting potential threats before they can cause harm.


Source: Bleeping Computer — 2026-08-04