CYBERSECURITYTRACKER
TRACKING7,159 stories in this site build1,507 vulnerability news stories in this site build
Permanent story citation

Phishing service spoofs RingCentral to steal Microsoft 365 accounts

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3856

As cited

Copy frozen at (site build).

threat intel

Phishing service spoofs RingCentral to steal Microsoft 365 accounts

The Greatness phishing-as-a-service (PhaaS) platform has expanded its attack capabilities beyond credential harvesting to include adversary-in-the-middle attacks and device-code phishing, with recent campaigns spoofing RingCentral to compromise Microsoft 365 accounts. This evolution demonstrates how commercially available phishing tools are becoming more sophisticated in their methods to bypass authentication controls.

Why it matters: Microsoft 365 users and organizations relying on RingCentral integration are at risk of account compromise through multiple attack vectors that standard email filtering may not detect; practitioners should implement conditional access policies, monitor for anomalous sign-ins, and enforce hardware-backed security keys where possible.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Phishing service spoofs RingCentral to steal Microsoft 365 accounts

The Greatness phishing-as-a-service (PhaaS) platform has expanded its attack capabilities beyond credential harvesting to include adversary-in-the-middle attacks and device-code phishing, with recent campaigns spoofing RingCentral to compromise Microsoft 365 accounts. This evolution demonstrates how commercially available phishing tools are becoming more sophisticated in their methods to bypass authentication controls.

Why it matters: Microsoft 365 users and organizations relying on RingCentral integration are at risk of account compromise through multiple attack vectors that standard email filtering may not detect; practitioners should implement conditional access policies, monitor for anomalous sign-ins, and enforce hardware-backed security keys where possible.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary