Greatness PhaaS Spoofs RingCentral to Steal Microsoft 365 Accounts and Bypass MFA

Aug 7, 2026

Security researchers have uncovered a new phishing campaign leveraging the Greatness Phishing-as-a-Service (PhaaS) platform to impersonate RingCentral notifications and compromise Microsoft 365 accounts. Unlike traditional credential harvesting kits, Greatness has evolved into a sophisticated adversary-in-the-middle (AiTM) platform capable of stealing MFA-authenticated session tokens, allowing attackers to bypass multi-factor authentication and gain direct access to enterprise Microsoft 365 environments.

The campaign demonstrates how commercial phishing platforms continue to evolve, enabling even low-skilled threat actors to conduct highly effective attacks against organizations worldwide.

Attack Overview

Threat

RingCentral-themed Microsoft 365 phishing campaign

Threat Type

Phishing-as-a-Service (PhaaS), Adversary-in-the-Middle (AiTM)

Platform Used

Greatness PhaaS

Primary Target

Microsoft 365 users

Spoofed Brand

RingCentral

Credential Theft

Yes

MFA Bypass

Yes (Session Token Theft)

Affected Services

Outlook, Teams, SharePoint, OneDrive, Microsoft Graph

Distribution Method

Phishing emails

Known Targets

Organizations in the US, UK, Canada, Australia, South Africa

Status

Active campaign

How the Attack Works

Researchers observed attackers sending phishing emails disguised as legitimate RingCentral notifications.

Common email themes include:

  • New voicemail alerts

  • Performance review notifications

  • Business communication updates

Although these emails originate from unauthorized mail servers and fail SPF/DMARC validation, many still reach user inboxes.

Victims who click the embedded links are redirected to attacker-controlled infrastructure hosting a convincing Microsoft 365 login page that closely mimics Microsoft's authentication portal.

MFA No Longer Stops the Attack

The most significant evolution in the Greatness platform is its ability to steal MFA-approved authentication tokens.

Instead of only collecting usernames and passwords, attackers now capture authenticated session tokens after victims complete the Microsoft login process.

This enables attackers to:

  • Skip the authentication process entirely

  • Bypass multi-factor authentication

  • Access Microsoft 365 without triggering another MFA challenge

This technique significantly increases the success rate of phishing attacks because organizations relying solely on MFA may still experience account compromise.

What Attackers Access After Compromise

Once inside a Microsoft 365 account, threat actors can enumerate enterprise resources through Microsoft Graph.

Researchers observed attackers targeting:

  • Outlook mailboxes

  • Microsoft Teams conversations

  • SharePoint sites

  • OneDrive files

  • Contacts

  • Calendars

  • Registered applications

Such access enables attackers to conduct:

  • Business Email Compromise (BEC)

  • Internal phishing

  • Data theft

  • Lateral movement

  • Corporate espionage

  • Follow-on ransomware attacks

Possible Connection to the RingCentral Data Breach

Researchers believe the campaign may be linked to the recently disclosed RingCentral customer data breach.

Although not confirmed, investigators suspect attackers may have obtained customer email addresses from that incident and are using them to create highly targeted phishing campaigns impersonating RingCentral.

Using legitimate customer information significantly increases phishing credibility and improves success rates.

Greatness Continues to Evolve

Greatness has operated as a commercial phishing platform for approximately four years.

Initially focused on credential theft, it now supports advanced capabilities including:

  • Adversary-in-the-Middle phishing

  • Session cookie theft

  • MFA token capture

  • Microsoft 365 targeting

  • Google Workspace targeting

  • Yahoo account targeting

  • iCloud credential theft

The platform is reportedly advertised through Telegram channels with thousands of subscribers and is available as a subscription service for approximately $289 per month, lowering the barrier to entry for cybercriminals.

Why This Campaign Matters

This campaign highlights a growing trend in modern phishing operations.

Attackers are no longer attempting only to steal passwords.

Instead, they target authenticated sessions, allowing them to:

  • Defeat MFA protections

  • Maintain persistent account access

  • Blend into legitimate user activity

  • Increase the likelihood of successful Business Email Compromise

Organizations that rely exclusively on passwords and MFA should consider implementing additional protections such as conditional access policies, token protection, identity risk detection, and continuous authentication monitoring.

Indicators of the Campaign

Security teams should watch for:

  • Unexpected RingCentral emails

  • Voicemail notifications requesting Microsoft login

  • Performance review emails containing external links

  • Microsoft 365 logins from unfamiliar IP addresses

  • Suspicious Microsoft Graph activity

  • New OAuth sessions

  • Unusual mailbox access

  • Abnormal Teams or SharePoint activity

How Organizations Can Defend Against Similar Attacks

Organizations should implement a layered defense strategy that includes:

Strengthen Identity Security

  • Deploy phishing-resistant MFA where possible

  • Enable Conditional Access policies

  • Monitor authentication token usage

  • Review risky sign-ins regularly

Improve Email Security

  • Enforce SPF, DKIM, and DMARC

  • Block lookalike domains

  • Detect brand impersonation attempts

Increase Employee Awareness

Users should be trained to:

  • Verify unexpected voicemail notifications

  • Avoid clicking links in unsolicited emails

  • Confirm login requests independently

  • Report suspicious authentication prompts immediately

Regular phishing simulations help employees recognize increasingly sophisticated phishing techniques before they lead to compromise.

ClearPhish Insight

Modern phishing campaigns increasingly focus on stealing authenticated sessions instead of passwords. As attackers adopt adversary-in-the-middle frameworks like Greatness, organizations need security awareness programs that reflect these evolving tactics.

ClearPhish enables organizations to simulate realistic Microsoft 365 phishing scenarios—including brand impersonation, credential harvesting, and MFA-focused attacks—helping employees recognize and report sophisticated threats before they result in account compromise.

Key Takeaways

  • Greatness PhaaS now impersonates RingCentral to target Microsoft 365 users.

  • The platform steals MFA-authenticated session tokens, enabling MFA bypass.

  • Attackers gain access to Outlook, Teams, SharePoint, OneDrive, and other Microsoft 365 services.

  • The campaign may leverage email data exposed in the recent RingCentral breach.

  • Organizations should combine identity security controls with continuous phishing awareness training to defend against modern AiTM attacks.

Latest News

Greatness PhaaS Spoofs RingCentral to Steal Microsoft 365 Accounts and Bypass MFA

Greatness PhaaS Spoofs RingCentral to Steal Microsoft 365 Accounts and Bypass MFA

Greatness PhaaS Spoofs RingCentral to Steal Microsoft 365 Accounts and Bypass MFA

Greatness PhaaS Spoofs RingCentral to Steal Microsoft 365 Accounts and Bypass MFA

Greatness PhaaS Spoofs RingCentral to Steal Microsoft 365 Accounts and Bypass MFA

Aug 7, 2026

COLDCARD Wallet RNG Vulnerability Linked to $88.6M Bitcoin Theft: Thousands of Crypto Wallets at Risk

COLDCARD Wallet RNG Vulnerability Linked to $88.6M Bitcoin Theft: Thousands of Crypto Wallets at Risk

COLDCARD Wallet RNG Vulnerability Linked to $88.6M Bitcoin Theft: Thousands of Crypto Wallets at Risk

COLDCARD Wallet RNG Vulnerability Linked to $88.6M Bitcoin Theft: Thousands of Crypto Wallets at Risk

COLDCARD Wallet RNG Vulnerability Linked to $88.6M Bitcoin Theft: Thousands of Crypto Wallets at Risk

Aug 3, 2026

Fake Claude Desktop App on Bing Ads Spreads SectopRAT Malware: How the FakeAgent Campaign Works

Fake Claude Desktop App on Bing Ads Spreads SectopRAT Malware: How the FakeAgent Campaign Works

Fake Claude Desktop App on Bing Ads Spreads SectopRAT Malware: How the FakeAgent Campaign Works

Fake Claude Desktop App on Bing Ads Spreads SectopRAT Malware: How the FakeAgent Campaign Works

Fake Claude Desktop App on Bing Ads Spreads SectopRAT Malware: How the FakeAgent Campaign Works

Jul 24, 2026

South Korea Diplomatic Data Breach Exposes Information of 6,000 Foreign Affairs Personnel

South Korea Diplomatic Data Breach Exposes Information of 6,000 Foreign Affairs Personnel

South Korea Diplomatic Data Breach Exposes Information of 6,000 Foreign Affairs Personnel

South Korea Diplomatic Data Breach Exposes Information of 6,000 Foreign Affairs Personnel

South Korea Diplomatic Data Breach Exposes Information of 6,000 Foreign Affairs Personnel

Jul 23, 2026

Windows LegacyHive Zero-Day Exploit Grants Hackers Administrator Access

Windows LegacyHive Zero-Day Exploit Grants Hackers Administrator Access

Windows LegacyHive Zero-Day Exploit Grants Hackers Administrator Access

Windows LegacyHive Zero-Day Exploit Grants Hackers Administrator Access

Windows LegacyHive Zero-Day Exploit Grants Hackers Administrator Access

Jul 20, 2026

Google Gemini CLI Abused by Hackers as AI Malware Botnet Operator

Google Gemini CLI Abused by Hackers as AI Malware Botnet Operator

Google Gemini CLI Abused by Hackers as AI Malware Botnet Operator

Google Gemini CLI Abused by Hackers as AI Malware Botnet Operator

Google Gemini CLI Abused by Hackers as AI Malware Botnet Operator

Jul 16, 2026

Get updates in your inbox directly

You are now subscribed.

Get updates in your inbox directly

You are now subscribed.

Get updates in your

inbox directly

You are now subscribed.

Get updates in your inbox directly

You are now subscribed.

Enable your employees as first line of defense and expand your digital footprints without any fear.

Enable your employees as first line of defense and expand your digital footprints without any fear.

Enable your employees as first line of defense and expand your digital footprints without any fear.

Enable your employees as first line of defense and expand your digital footprints without any fear.