How Microsoft 365 Phishing Attacks Are Bypassing MFA Using RingCentral Spoofing

Discover how the Greatness phishing operation targets Microsoft 365 users by spoofing RingCentral emails, stealing MFA tokens and accessing Outlook, Teams, and OneDrive data.

How Microsoft 365 Phishing Attacks Are Bypassing MFA Using RingCentral Spoofing
Sarah Collins

Sarah Collins

Computing Editor

Specializes in PCs, laptops, components, and productivity-focused computing tech.

What is the new Microsoft 365 phishing threat involving RingCentral?

Recent phishing attacks targeting Microsoft 365 users are leveraging emails that impersonate RingCentral, a popular communication platform. These emails contain fake voicemail or performance review notifications designed to lure recipients into clicking links that lead to counterfeit Microsoft 365 login pages. The phishing platform called Greatness has evolved sufficiently to bypass multi-factor authentication (MFA) by capturing MFA-approved tokens, enabling attackers to access users' accounts despite additional layers of security.

How does this attack bypass multi-factor authentication?

พบแคมเปญฟิชชิงปลอม RingCentral มุ่งโจมตีผู้ใช้ Microsoft 365 - Hostatom Web  Hosting
พบแคมเปญฟิชชิงปลอม RingCentral มุ่งโจมตีผู้ใช้ Microsoft 365 - Hostatom Web Hosting

Traditional MFA protection relies on an additional verification step beyond the password, but the Greatness phishing-as-a-service exploits a technique that intercepts valid MFA tokens during the login process. When victims enter their credentials and complete MFA on the fake login page, the attacker captures the authentication token that grants access. This token can then be used to access Microsoft 365 services without triggering further authentication requests. This approach allows attackers to seamlessly access Outlook emails, Teams conversations, SharePoint content, OneDrive files, calendars, contacts, and more.

Who is affected and how widespread is this phishing operation?

Victims primarily include Microsoft 365 users in regions such as the US, UK, Australia, Canada, and South Africa. Greatness has a history of targeting accounts across various platforms, including iCloud, Yahoo, and Google Workspace, indicating a broad threat landscape. The RingCentral spoofing leverages potentially leaked customer data following a breach by the ShinyHunters hacker group, increasing the credibility of the phishing emails. The phishing-as-a-service model means that this attack is commercially available for as much as $289 per month via Telegram channels, facilitating easy access to these sophisticated phishing tools for cybercriminals worldwide.

What are the practical steps Microsoft 365 users should take to protect themselves?

Phishing service spoofs RingCentral to steal Microsoft 365 accounts
Phishing service spoofs RingCentral to steal Microsoft 365 accounts

To mitigate this risk, Microsoft 365 users should:

  • Be highly vigilant with unexpected emails claiming to be from RingCentral, especially those prompting urgent action on voicemails or performance reviews.
  • Manually verify communications by accessing RingCentral services directly rather than clicking email links.
  • Enable additional protective measures such as conditional access policies, identity protection tools, and monitoring unusual login activity in Microsoft 365.
  • Educate users about phishing tactics that use credential and token harvesting, emphasizing skepticism of suspicious login pages even when MFA is requested.
  • Maintain endpoint security and keep software up to date to reduce susceptibility to phishing payloads and browser exploits that automate token theft.

Understanding the broader implications of phishing-as-a-service (PhaaS)

The availability of Greatness as a subscription-based phishing service allows attackers of varying skill levels to conduct targeted credential theft and MFA bypass attacks. This commodification of phishing tools increases the volume and sophistication of attacks, making it essential for organizations to adopt layered security defenses and user training. It also underscores the limitations of MFA relying solely on standard token exchanges without additional contextual or behavioral risk analysis.

React to this story

Related Posts