highPhishing

Greatness Phishing-as-a-Service Targeting Microsoft 365 via RingCentral Spoofing

First seen Aug 5, 2026 · Updated Aug 5, 2026

phishingPhaaSMicrosoft 365adversary-in-the-middledevice-code phishingcredential theftbusiness-email-compromiseagent-relevant

The Greatness phishing-as-a-service platform has evolved from basic credential phishing to adversary-in-the-middle (AiTM) and device-code phishing techniques, now spoofing RingCentral notifications to target Microsoft 365 accounts. This expansion enables attackers to bypass MFA protections and steal session tokens, significantly increasing the risk of successful account takeovers across organizations using Microsoft 365.

Technical Analysis

Greatness PhaaS operators craft phishing emails impersonating RingCentral voicemail or fax notifications, directing victims to spoofed Microsoft 365 login pages. The platform now supports AiTM proxy techniques that intercept authentication traffic in real time, capturing session cookies and tokens to bypass MFA, alongside device-code phishing flows that abuse legitimate OAuth device authorization grants to trick users into authorizing attacker-controlled sessions. Because Microsoft 365 credentials and OAuth tokens are frequently used by AI agent frameworks and RAG pipelines to authenticate to Graph API, SharePoint, Outlook, and Teams connectors for automated data retrieval and action-taking, compromised tokens from this campaign could allow attackers to hijack agent-driven workflows, exfiltrate sensitive organizational data via agent tool access, or pivot into connected cloud services.

Affected Systems

Microsoft 365 accounts (Exchange Online, SharePoint, Teams, OneDrive), organizations using RingCentral for voice/fax communications, environments relying on OAuth device-code authentication flows

Indicators of Compromise

  • Phishing emails spoofing RingCentral voicemail/fax notifications
  • Spoofed Microsoft 365 login pages
  • AiTM proxy infrastructure (domains not disclosed in source)
  • Device-code phishing authorization prompts

Remediation Steps

  1. 1

    Enforce phishing-resistant MFA

    Deploy FIDO2/WebAuthn-based hardware security keys for Microsoft 365 accounts to resist AiTM session token theft.

  2. 2

    Restrict device-code authentication flow

    Disable or tightly restrict OAuth device-code grant flow in Azure AD/Entra ID Conditional Access policies unless explicitly required.

  3. 3

    User awareness training

    Educate employees on recognizing spoofed RingCentral notifications and verifying login page URLs before entering credentials.

  4. 4

    Monitor for anomalous sign-ins

    Enable Microsoft 365 sign-in risk detection and alerting for impossible travel, unfamiliar sign-in properties, and token replay indicators.

  5. 5

    Rotate and audit OAuth tokens

    Review and revoke suspicious OAuth grants and session tokens, including those used by automation, bots, or AI agent integrations connected to Microsoft 365.

Industries Most Exposed

All industries using Microsoft 365with heightened risk for financeprofessional serviceshealthcareand technology sectors

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.