Greatness Phishing-as-a-Service Targeting Microsoft 365 via RingCentral Spoofing
First seen Aug 5, 2026 · Updated Aug 5, 2026
The Greatness phishing-as-a-service platform has evolved from basic credential phishing to adversary-in-the-middle (AiTM) and device-code phishing techniques, now spoofing RingCentral notifications to target Microsoft 365 accounts. This expansion enables attackers to bypass MFA protections and steal session tokens, significantly increasing the risk of successful account takeovers across organizations using Microsoft 365.
Technical Analysis
Greatness PhaaS operators craft phishing emails impersonating RingCentral voicemail or fax notifications, directing victims to spoofed Microsoft 365 login pages. The platform now supports AiTM proxy techniques that intercept authentication traffic in real time, capturing session cookies and tokens to bypass MFA, alongside device-code phishing flows that abuse legitimate OAuth device authorization grants to trick users into authorizing attacker-controlled sessions. Because Microsoft 365 credentials and OAuth tokens are frequently used by AI agent frameworks and RAG pipelines to authenticate to Graph API, SharePoint, Outlook, and Teams connectors for automated data retrieval and action-taking, compromised tokens from this campaign could allow attackers to hijack agent-driven workflows, exfiltrate sensitive organizational data via agent tool access, or pivot into connected cloud services.
Affected Systems
Microsoft 365 accounts (Exchange Online, SharePoint, Teams, OneDrive), organizations using RingCentral for voice/fax communications, environments relying on OAuth device-code authentication flows
Indicators of Compromise
- Phishing emails spoofing RingCentral voicemail/fax notifications
- Spoofed Microsoft 365 login pages
- AiTM proxy infrastructure (domains not disclosed in source)
- Device-code phishing authorization prompts
Remediation Steps
- 1
Enforce phishing-resistant MFA
Deploy FIDO2/WebAuthn-based hardware security keys for Microsoft 365 accounts to resist AiTM session token theft.
- 2
Restrict device-code authentication flow
Disable or tightly restrict OAuth device-code grant flow in Azure AD/Entra ID Conditional Access policies unless explicitly required.
- 3
User awareness training
Educate employees on recognizing spoofed RingCentral notifications and verifying login page URLs before entering credentials.
- 4
Monitor for anomalous sign-ins
Enable Microsoft 365 sign-in risk detection and alerting for impossible travel, unfamiliar sign-in properties, and token replay indicators.
- 5
Rotate and audit OAuth tokens
Review and revoke suspicious OAuth grants and session tokens, including those used by automation, bots, or AI agent integrations connected to Microsoft 365.
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.