Breaking
Cyber CrimeDeveloping Story

RingCentral Spoof Hijacks M365 Accounts

Phishing service Greatness uses spoofed RingCentral emails to bypass MFA and compromise Microsoft 365 accounts.

··2 hours ago·3 min read
padlock on laptop with light trails
Photo by FlyD on Unsplash

A corporate phishing platform has expanded its operations to breach multi-factor authentication defenses across enterprise Microsoft 365 deployments. According to research published by cybersecurity firm ZeroBEC, threat actors are deploying spoofed RingCentral communications designed to siphon valid session tokens directly from victim organizations.

Fake Notifications Direct Victims to Attack Infrastructure

The attack sequence relies on targeted email messages crafted to impersonate genuine administrative communications from business communications provider RingCentral. Researchers at ZeroBEC reported that targets receive deceptive notices, specifically framed as standard fake voicemail alerts or performance-review notifications.

Despite their legitimate appearance to end users, technical analysis reveals these messages originate from unrecognized mail servers. The incoming phishing emails consistently fail both Sender Policy Framework (SPF) and Domain-based Message Authentication, Reporting, and Conformance (DMARC) validation checks.

When recipients click the embedded links within these alerts, they are redirected away from corporate channels onto attacker-controlled infrastructure hosting a spoofed Microsoft 365 login page designed to mimic official authentication portals.

Token Theft Mechanism Bypasses Authentication Controls

The malicious landing page operates as an intermediary interface through the Greatness phishing-as-a-service platform. Rather than solely harvesting static credentials, the service captures active MFA-approved authentication tokens during the user's logon session.

By capturing these session tokens in real time, the operators behind Greatness effectively circumvent secondary security verification measures without needing to manipulate or break the underlying multi-factor protocol itself. Once the valid token is acquired, attackers obtain direct entrance to target enterprise accounts.

Data Enumeration Across Microsoft Graph Infrastructure

After acquiring valid session tokens, adversaries systematically search compromised environments for sensitive operational data. Researchers report that Greatness operators routinely enumerate email mailboxes within Outlook, active corporate messaging threads inside Teams, and shared enterprise documentation hosted on SharePoint sites.

The intrusions further extend into cloud file repositories and organizational directory structures. Through the programmatic query capabilities of Microsoft Graph, attackers extract OneDrive files, employee contact directories, calendar schedules, and administrative records linked to registered applications within the targeted tenant.

Potential Link to Previous Breach at RingCentral

Security analysts at ZeroBEC noted that the choice of spoofing target coincides with a prior security incident affecting RingCentral. Cybercriminal group ShinyHunters previously conducted a data breach against RingCentral, creating the possibility that stolen customer records contributed to the current phishing activity.

Researchers observe that while an explicit link remains unconfirmed, threat actors likely exfiltrated a directory of RingCentral customer email addresses during that breach. This victim list provides attackers with a tailored recipient pool, increasing the plausibility of their impersonation campaigns.

Four Years of Targeted International Operations

While the focus on RingCentral impersonation represents a specific tactic, the underlying Greatness PhaaS service maintains a longer operational history. According to ZeroBEC, the platform has actively sustained operations for at least four years across multiple geographic markets.

Although the platform originally functioned as a conventional credential-harvesting service, it has since evolved to target accounts across iCloud, Yahoo, and Google Workspace in addition to Microsoft 365 environments. Campaign activity has specifically impacted organization targets located across five primary regions:

  • US enterprise and organizational account holders
  • UK commercial and public sector endpoints
  • Australia business environments and user accounts
  • Canada corporate and institutional targets
  • South Africa network infrastructure and user profiles

Commercial Availability Across Underground Channels

The infrastructure powering these attacks is distributed widely across illicit criminal marketplaces. As reported by BleepingComputer, the Greatness service is actively marketed to potential buyers through Telegram channels that hold subscriber counts in the thousands.

Access to the platform's toolset and hosting capabilities is sold under a subscription model. The service is currently offered to purchasers for a recurring monthly fee of $289, lowering the technical barrier to entry for conducting token-stealing phishing campaigns.

Enterprise Consequences and Risk Mitigation

The continuous evolution of phishing-as-a-service toolkits indicates that traditional perimeter defenses and password-based controls offer diminished protection when session tokens can be intercepted externally. Because these attacks bypass standard multi-factor prompts by proxying active logins, organizations relying solely on basic MFA configurations face heightened risk of post-authentication exposure.

Defenders managing enterprise cloud infrastructure may need to evaluate strict email validation policies—including automatic dropping of messages failing SPF and DMARC—while implementing token protection controls and monitoring Microsoft Graph API queries for unusual data harvesting activity.

#phishing#microsoft 365#mfa bypass#ringcentral#phaas

Sources

Iliyas

Editor, Xploitwire

This article was researched and drafted with AI assistance from the sources listed above, then checked against those sources through our automated fact-check process, under the editorial policies set by Iliyas. Our AI Policy →

← Back to all stories