Scam Radar

How can you recognize Greatness phishing service uses RingCentral spoofing and AiTM attacks to steal Microsoft 365 accounts?

Published

Listen to the episode

TLDR

The Greatness phishing as a service platform has added adversary in the middle (AiTM) and device code phishing flows to steal Microsoft 365 logins. Attackers send emails that appear to come from RingCentral (service@ringcentral[.]com),...

How it works

The Greatness phishing as a service platform has added adversary in the middle (AiTM) and device code phishing flows to steal Microsoft 365 logins. Attackers send emails that appear to come from RingCentral (service@ringcentral[.]com),...

Red flags

  • Unexpected RingCentral voicemail or HR notifications urging you to click a button or sign in. Sender passed only because RingCentral is on the organization's safe sender whitelist (failed SPF/DMARC, no DKIM). Microsoft 365 login page opened via a button in an email rather than a direct browser navigation

What to do

  1. 1Verify any voicemail or review notice by logging into RingCentral directly, never via the email link. Report suspicious M365 sign ins from unfamiliar hosting/VPN IPs to your IT or security team immediately. Revoke active sessions and refresh tokens if you entered credentials
  2. 2remove blanket RingCentral domain exclusions and require valid SPF/DKIM/DMARC before trusting ma

Source

FAQ

Is Greatness phishing service uses RingCentral spoofing and AiTM attacks to steal Microsoft 365 accounts a real scam pattern?

Yes. Treat the message, call, or payment request as suspicious until you verify it through an official channel.

What are the first warning signs?

Unexpected RingCentral voicemail or HR notifications urging you to click a button or sign in. Sender passed only because RingCentral is on the organization's safe sender whitelist (failed SPF/DMARC, no DKIM). Microsoft 365 login page opened via a button in an email rather than a direct browser navigation

What should I do first?

Verify any voicemail or review notice by logging into RingCentral directly, never via the email link. Report suspicious M365 sign ins from unfamiliar hosting/VPN IPs to your IT or security team immediately. Revoke active sessions and refresh tokens if you entered credentials; remove blanket RingCentral domain exclusions and require valid SPF/DKIM/DMARC before trusting ma

Can LegalAudit check my case?

Yes. Start a free chat and paste the message, link, sender, or payment details for triage.