Greatness phishing service spoofs RingCentral emails to steal Microsoft 365 accounts

A phishing-for-hire service called Greatness is sending fake RingCentral emails to steal Microsoft 365 accounts from real business users. Researchers say the campaign abuses organizations' RingCentral safe-sender trust to get phishing emails delivered, then routes victims to either an adversary-in-the-middle login flow that steals a valid multi-factor authentication session token or a device-code phishing flow. Stolen tokens were replayed through VPN and VPS infrastructure to access Outlook, Teams, SharePoint, OneDrive, calendars, contacts, and Microsoft Graph data.
Why it matters: This is a practical account-takeover threat affecting organizations that use Microsoft 365 and trust RingCentral mail. Defenders should review safe-sender and allowlist rules, hunt for suspicious MFA-approved sign-ins and token reuse, and revoke active sessions and refresh tokens if compromise is suspected.

Sources

Phishing service spoofs RingCentral to steal Microsoft 365 accounts
Bill Toulas 2026.08.04 100% relevant
This article establishes a concrete new campaign around the Greatness phishing service's use of spoofed RingCentral messages to bypass trust controls and steal Microsoft 365 access.
← Back to all stories