<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/phishing-service-spoofs-ringcentral-to-steal-microsoft-365-accounts-ajuhddfzc" -->

---
title: Phishing service spoofs RingCentral to steal Microsoft...
description: The Greatness phishing-as-a-service (PhaaS) platform has expanded its capabilities to include adversary-in-the-middle (AiTM) and device-code phishing attacks...
canonical: https://daily.dev/posts/phishing-service-spoofs-ringcentral-to-steal-microsoft-365-accounts-ajuhddfzc
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Phishing service spoofs RingCentral to steal Microsoft 365 accounts | daily.dev
og:description: The Greatness phishing-as-a-service (PhaaS) platform has expanded its capabilities to include adversary-in-the-middle (AiTM) and device-code phishing attacks...
og:url: https://daily.dev/posts/phishing-service-spoofs-ringcentral-to-steal-microsoft-365-accounts-ajuhddfzc
og:image: https://api.daily.dev/og/posts/AjUhddfZC.png
og:image:alt: Phishing service spoofs RingCentral to steal Microsoft 365 accounts
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Phishing service spoofs RingCentral to steal Microsoft 365 accounts

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 3 min read · 0 upvotes · 0 comments

## Summary

The Greatness phishing-as-a-service (PhaaS) platform has expanded its capabilities to include adversary-in-the-middle (AiTM) and device-code phishing attacks targeting Microsoft 365 accounts. In a recent campaign, attackers spoofed RingCentral communications by impersonating service@ringcentral.com with fake voicemail and performance-review lures. Despite failing SPF, DMARC, and DKIM checks, emails bypassed filters because RingCentral was whitelisted, achieving a Spam Confidence Level of -1 on Microsoft Exchange. Victims were routed to Greatness infrastructure where MFA-approved authentication tokens were captured and later replayed from VPS/VPN infrastructure to access compromised accounts. Attackers then enumerated Outlook, Teams, SharePoint, OneDrive, and other Microsoft 365 services via Microsoft Graph, with access persisting over two weeks. Researchers suspect attackers may have obtained valid RingCentral user targets from a recent ShinyHunters data breach. Recommended mitigations include auditing safe-sender lists, hunting for suspicious MFA sign-ins, and revoking tokens if compromise is suspected.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/phishing-service-spoofs-ringcentral-to-steal-microsoft-365-accounts>

## Similar posts on daily.dev

- [New Forg365 phishing platform uses AI to target Microsoft 365 accounts](https://daily.dev/posts/new-forg365-phishing-platform-uses-ai-to-target-microsoft-365-accounts-x0k2qzzbc) · BleepingComputer · 0 upvotes · 0 comments
- [Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](https://daily.dev/posts/spring-ring-an-inside-look-at-voice-phishing-campaigns-in-microsoft-teams-h24go8gif) · Unit 42 · 0 upvotes · 0 comments

---

Tags: [#microsoft](https://daily.dev/tags/microsoft), [#phishing](https://daily.dev/tags/phishing)

[View this post on daily.dev](https://daily.dev/posts/phishing-service-spoofs-ringcentral-to-steal-microsoft-365-accounts-ajuhddfzc)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Phishing service spoofs RingCentral to steal Microsoft 365 accounts","url":"https://daily.dev/posts/phishing-service-spoofs-ringcentral-to-steal-microsoft-365-accounts-ajuhddfzc","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/phishing-service-spoofs-ringcentral-to-steal-microsoft-365-accounts-ajuhddfzc"},"datePublished":"2026-08-04T21:45:40.684Z","dateModified":"2026-08-04T21:46:11.127Z","description":"The Greatness phishing-as-a-service (PhaaS) platform has expanded its capabilities to include adversary-in-the-middle (AiTM) and device-code phishing attacks...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/5de2c9b73f7a6aa216c4090d67ab8401?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/5de2c9b73f7a6aa216c4090d67ab8401?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"BleepingComputer","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"BleepingComputer","logo":"https://media.daily.dev/image/upload/s--as8nJ3qy--/f_auto,q_auto/v1774959951/logos/bleepingcomputer?_a=BAMAMiWQ0","url":"https://daily.dev/sources/bleepingcomputer"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/phishing-service-spoofs-ringcentral-to-steal-microsoft-365-accounts-ajuhddfzc","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"microsoft,phishing","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"BleepingComputer","item":"https://daily.dev/sources/bleepingcomputer"},{"@type":"ListItem","position":3,"name":"Phishing service spoofs RingCentral to steal Microsoft 365 accounts"}]}
```

