Executive Summary
In August 2026, the 'Greatness' phishing-as-a-service platform expanded its operations to include adversary-in-the-middle attacks and device-code phishing, specifically targeting Microsoft 365 accounts. Cybercriminals leveraged this platform to impersonate RingCentral, a widely-used communications service, by sending fraudulent emails that appeared to originate from service@ringcentral.com. These emails, often containing fake voicemail and performance-review notifications, successfully bypassed email security filters due to RingCentral's whitelisted status. Upon clicking embedded links, victims were redirected to phishing sites designed to capture authentication tokens, enabling attackers to access and exfiltrate data from Outlook, Teams, SharePoint, and OneDrive, with unauthorized access persisting for over two weeks in some instances.
This incident underscores a significant evolution in phishing tactics, highlighting the increasing sophistication of phishing-as-a-service platforms and their ability to exploit trusted services to bypass security measures. The use of adversary-in-the-middle techniques to capture multi-factor authentication tokens represents a notable advancement in cybercriminal methodologies, emphasizing the need for organizations to continually adapt their security protocols to counteract these evolving threats.
Why This Matters Now
The 'Greatness' phishing campaign's exploitation of trusted platforms like RingCentral to bypass security measures highlights the urgent need for organizations to reassess and strengthen their email security protocols. The increasing sophistication of phishing-as-a-service platforms poses a significant threat to sensitive data, emphasizing the importance of continuous vigilance and adaptation to emerging cyber threats.
Attack Path Analysis
The attack began with phishing emails impersonating RingCentral, leading victims to malicious Microsoft 365 login pages. Upon credential submission, attackers obtained authentication tokens, enabling unauthorized access to Microsoft 365 services. They then enumerated Outlook mailboxes, Teams conversations, SharePoint sites, OneDrive files, contacts, calendars, and registered applications. The attackers maintained persistent access for over two weeks, exfiltrating sensitive data. The impact included unauthorized access to confidential information and potential data breaches.
Kill Chain Progression
Initial Compromise
Description
Attackers sent phishing emails spoofing RingCentral, leading victims to malicious Microsoft 365 login pages.
MITRE ATT&CK® Techniques
Spearphishing Attachment
Web Protocols
Multi-Factor Authentication Interception
Valid Accounts
Email Collection
Data from Information Repositories
Cloud Accounts
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure that security policies and operational procedures for managing vulnerabilities are documented, in use, and known to all affected parties.
Control ID: 6.4.3
NYDFS 23 NYCRR 500 – Encryption of Nonpublic Information
Control ID: 500.15
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Implement strong authentication mechanisms
Control ID: Identity and Access Management
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
Microsoft 365 phishing-as-a-service attacks bypass MFA through adversary-in-the-middle techniques, compromising authentication tokens and enabling prolonged unauthorized access to enterprise systems.
Telecommunications
RingCentral platform spoofing exploits communication service trust relationships to bypass email security filters, targeting businesses dependent on unified communications infrastructure for operations.
Financial Services
Egress security failures and lateral movement risks expose sensitive financial data through compromised Microsoft Graph access, violating PCI compliance requirements for payment processing organizations.
Health Care / Life Sciences
Zero trust segmentation weaknesses allow healthcare credential compromise through device-code phishing, threatening HIPAA compliance and patient data protection in Microsoft 365 environments.
Sources
- Phishing service spoofs RingCentral to steal Microsoft 365 accountshttps://www.bleepingcomputer.com/news/security/phishing-service-spoofs-ringcentral-to-steal-microsoft-365-accounts/Verified
- Inside Greatness: Telegram-Distributed M365 AiTM PhaaShttps://zerobec.com/blog/greatness-phaas-aitm-and-device-code-phishingVerified
- RingCentral, Inc. Listed by ShinyHunters Ransomware Grouphttps://www.galaxywarden.com/blog/breach/ringcentral-inc-shinyhunters-2026-07
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have limited the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-aware access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix CNSF primarily focuses on network-level controls, it could have limited the attacker's ability to exploit compromised credentials by enforcing strict segmentation and identity-aware access controls.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation would likely have limited the attacker's ability to escalate privileges by enforcing strict access controls based on identity and context.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security would likely have limited the attacker's ability to move laterally between services by enforcing strict segmentation and monitoring internal traffic.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control would likely have limited the attacker's ability to maintain persistent access by providing comprehensive monitoring and control over cloud environments.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement would likely have limited the attacker's ability to exfiltrate data by enforcing strict egress controls and monitoring outbound traffic.
Aviatrix Zero Trust CNSF would likely have limited the overall impact of the incident by reducing the attacker's ability to access and exfiltrate sensitive data through strict segmentation and access controls.
Impact at a Glance
Affected Business Functions
- Email Communications
- Document Management
- Collaboration Tools
- VoIP Services
Estimated downtime: 14 days
Estimated loss: $500,000
Potential exposure of sensitive corporate communications, internal documents, and confidential business information.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement within Microsoft 365 services.
- • Enforce Egress Security & Policy Enforcement to monitor and control outbound data transfers.
- • Utilize Multicloud Visibility & Control to detect and respond to anomalous activities across cloud services.
- • Deploy Threat Detection & Anomaly Response mechanisms to identify and mitigate suspicious behaviors.
- • Regularly audit and update safe-sender lists to prevent phishing emails from bypassing security filters.



