Listen to the episode
TLDR
The Greatness phishing as a service platform has added adversary in the middle (AiTM) and device code phishing flows to steal Microsoft 365 logins. Attackers send emails that appear to come from RingCentral (service@ringcentral[.]com),...
How it works
The Greatness phishing as a service platform has added adversary in the middle (AiTM) and device code phishing flows to steal Microsoft 365 logins. Attackers send emails that appear to come from RingCentral (service@ringcentral[.]com),...
Red flags
- Unexpected RingCentral voicemail or HR notifications urging you to click a button or sign in. Sender passed only because RingCentral is on the organization's safe sender whitelist (failed SPF/DMARC, no DKIM). Microsoft 365 login page opened via a button in an email rather than a direct browser navigation
What to do
- 1Verify any voicemail or review notice by logging into RingCentral directly, never via the email link. Report suspicious M365 sign ins from unfamiliar hosting/VPN IPs to your IT or security team immediately. Revoke active sessions and refresh tokens if you entered credentials
- 2remove blanket RingCentral domain exclusions and require valid SPF/DKIM/DMARC before trusting ma
Source
bleepingcomputer
Source reviewed by Mythos Forensic Team
https://www.bleepingcomputer.com/news/security/phishing-service-spoofs-ringcentral-to-steal-microsoft-365-accounts/FAQ
Is Greatness phishing service uses RingCentral spoofing and AiTM attacks to steal Microsoft 365 accounts a real scam pattern?
Yes. Treat the message, call, or payment request as suspicious until you verify it through an official channel.
What are the first warning signs?
Unexpected RingCentral voicemail or HR notifications urging you to click a button or sign in. Sender passed only because RingCentral is on the organization's safe sender whitelist (failed SPF/DMARC, no DKIM). Microsoft 365 login page opened via a button in an email rather than a direct browser navigation
What should I do first?
Verify any voicemail or review notice by logging into RingCentral directly, never via the email link. Report suspicious M365 sign ins from unfamiliar hosting/VPN IPs to your IT or security team immediately. Revoke active sessions and refresh tokens if you entered credentials; remove blanket RingCentral domain exclusions and require valid SPF/DKIM/DMARC before trusting ma
Can LegalAudit check my case?
Yes. Start a free chat and paste the message, link, sender, or payment details for triage.