Greatness PhaaS Spoofs RingCentral to Steal Microsoft 365 Accounts and Bypass MFA
Aug 7, 2026
Security researchers have uncovered a new phishing campaign leveraging the Greatness Phishing-as-a-Service (PhaaS) platform to impersonate RingCentral notifications and compromise Microsoft 365 accounts. Unlike traditional credential harvesting kits, Greatness has evolved into a sophisticated adversary-in-the-middle (AiTM) platform capable of stealing MFA-authenticated session tokens, allowing attackers to bypass multi-factor authentication and gain direct access to enterprise Microsoft 365 environments.
The campaign demonstrates how commercial phishing platforms continue to evolve, enabling even low-skilled threat actors to conduct highly effective attacks against organizations worldwide.
Attack Overview
Threat | RingCentral-themed Microsoft 365 phishing campaign |
|---|---|
Threat Type | Phishing-as-a-Service (PhaaS), Adversary-in-the-Middle (AiTM) |
Platform Used | Greatness PhaaS |
Primary Target | Microsoft 365 users |
Spoofed Brand | RingCentral |
Credential Theft | Yes |
MFA Bypass | Yes (Session Token Theft) |
Affected Services | Outlook, Teams, SharePoint, OneDrive, Microsoft Graph |
Distribution Method | Phishing emails |
Known Targets | Organizations in the US, UK, Canada, Australia, South Africa |
Status | Active campaign |
How the Attack Works
Researchers observed attackers sending phishing emails disguised as legitimate RingCentral notifications.
Common email themes include:
New voicemail alerts
Performance review notifications
Business communication updates
Although these emails originate from unauthorized mail servers and fail SPF/DMARC validation, many still reach user inboxes.
Victims who click the embedded links are redirected to attacker-controlled infrastructure hosting a convincing Microsoft 365 login page that closely mimics Microsoft's authentication portal.
MFA No Longer Stops the Attack
The most significant evolution in the Greatness platform is its ability to steal MFA-approved authentication tokens.
Instead of only collecting usernames and passwords, attackers now capture authenticated session tokens after victims complete the Microsoft login process.
This enables attackers to:
Skip the authentication process entirely
Bypass multi-factor authentication
Access Microsoft 365 without triggering another MFA challenge
This technique significantly increases the success rate of phishing attacks because organizations relying solely on MFA may still experience account compromise.
What Attackers Access After Compromise
Once inside a Microsoft 365 account, threat actors can enumerate enterprise resources through Microsoft Graph.
Researchers observed attackers targeting:
Outlook mailboxes
Microsoft Teams conversations
SharePoint sites
OneDrive files
Contacts
Calendars
Registered applications
Such access enables attackers to conduct:
Business Email Compromise (BEC)
Internal phishing
Data theft
Lateral movement
Corporate espionage
Follow-on ransomware attacks
Possible Connection to the RingCentral Data Breach
Researchers believe the campaign may be linked to the recently disclosed RingCentral customer data breach.
Although not confirmed, investigators suspect attackers may have obtained customer email addresses from that incident and are using them to create highly targeted phishing campaigns impersonating RingCentral.
Using legitimate customer information significantly increases phishing credibility and improves success rates.
Greatness Continues to Evolve
Greatness has operated as a commercial phishing platform for approximately four years.
Initially focused on credential theft, it now supports advanced capabilities including:
Adversary-in-the-Middle phishing
Session cookie theft
MFA token capture
Microsoft 365 targeting
Google Workspace targeting
Yahoo account targeting
iCloud credential theft
The platform is reportedly advertised through Telegram channels with thousands of subscribers and is available as a subscription service for approximately $289 per month, lowering the barrier to entry for cybercriminals.
Why This Campaign Matters
This campaign highlights a growing trend in modern phishing operations.
Attackers are no longer attempting only to steal passwords.
Instead, they target authenticated sessions, allowing them to:
Defeat MFA protections
Maintain persistent account access
Blend into legitimate user activity
Increase the likelihood of successful Business Email Compromise
Organizations that rely exclusively on passwords and MFA should consider implementing additional protections such as conditional access policies, token protection, identity risk detection, and continuous authentication monitoring.
Indicators of the Campaign
Security teams should watch for:
Unexpected RingCentral emails
Voicemail notifications requesting Microsoft login
Performance review emails containing external links
Microsoft 365 logins from unfamiliar IP addresses
Suspicious Microsoft Graph activity
New OAuth sessions
Unusual mailbox access
Abnormal Teams or SharePoint activity
How Organizations Can Defend Against Similar Attacks
Organizations should implement a layered defense strategy that includes:
Strengthen Identity Security
Deploy phishing-resistant MFA where possible
Enable Conditional Access policies
Monitor authentication token usage
Review risky sign-ins regularly
Improve Email Security
Enforce SPF, DKIM, and DMARC
Block lookalike domains
Detect brand impersonation attempts
Increase Employee Awareness
Users should be trained to:
Verify unexpected voicemail notifications
Avoid clicking links in unsolicited emails
Confirm login requests independently
Report suspicious authentication prompts immediately
Regular phishing simulations help employees recognize increasingly sophisticated phishing techniques before they lead to compromise.
ClearPhish Insight
Modern phishing campaigns increasingly focus on stealing authenticated sessions instead of passwords. As attackers adopt adversary-in-the-middle frameworks like Greatness, organizations need security awareness programs that reflect these evolving tactics.
ClearPhish enables organizations to simulate realistic Microsoft 365 phishing scenarios—including brand impersonation, credential harvesting, and MFA-focused attacks—helping employees recognize and report sophisticated threats before they result in account compromise.
Key Takeaways
Greatness PhaaS now impersonates RingCentral to target Microsoft 365 users.
The platform steals MFA-authenticated session tokens, enabling MFA bypass.
Attackers gain access to Outlook, Teams, SharePoint, OneDrive, and other Microsoft 365 services.
The campaign may leverage email data exposed in the recent RingCentral breach.
Organizations should combine identity security controls with continuous phishing awareness training to defend against modern AiTM attacks.






