Validated Containment Architectures are here. →Explore

Executive Summary

In August 2026, the 'Greatness' phishing-as-a-service platform expanded its operations to include adversary-in-the-middle attacks and device-code phishing, specifically targeting Microsoft 365 accounts. Cybercriminals leveraged this platform to impersonate RingCentral, a widely-used communications service, by sending fraudulent emails that appeared to originate from service@ringcentral.com. These emails, often containing fake voicemail and performance-review notifications, successfully bypassed email security filters due to RingCentral's whitelisted status. Upon clicking embedded links, victims were redirected to phishing sites designed to capture authentication tokens, enabling attackers to access and exfiltrate data from Outlook, Teams, SharePoint, and OneDrive, with unauthorized access persisting for over two weeks in some instances.

This incident underscores a significant evolution in phishing tactics, highlighting the increasing sophistication of phishing-as-a-service platforms and their ability to exploit trusted services to bypass security measures. The use of adversary-in-the-middle techniques to capture multi-factor authentication tokens represents a notable advancement in cybercriminal methodologies, emphasizing the need for organizations to continually adapt their security protocols to counteract these evolving threats.

Why This Matters Now

The 'Greatness' phishing campaign's exploitation of trusted platforms like RingCentral to bypass security measures highlights the urgent need for organizations to reassess and strengthen their email security protocols. The increasing sophistication of phishing-as-a-service platforms poses a significant threat to sensitive data, emphasizing the importance of continuous vigilance and adaptation to emerging cyber threats.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The incident revealed vulnerabilities in email security protocols, particularly in the reliance on whitelisting trusted services without adequate verification, allowing malicious emails to bypass filters.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Aviatrix Zero Trust CNSF is pertinent to this incident as it could have limited the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-aware access controls.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: While Aviatrix CNSF primarily focuses on network-level controls, it could have limited the attacker's ability to exploit compromised credentials by enforcing strict segmentation and identity-aware access controls.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Aviatrix Zero Trust Segmentation would likely have limited the attacker's ability to escalate privileges by enforcing strict access controls based on identity and context.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Aviatrix East-West Traffic Security would likely have limited the attacker's ability to move laterally between services by enforcing strict segmentation and monitoring internal traffic.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Aviatrix Multicloud Visibility & Control would likely have limited the attacker's ability to maintain persistent access by providing comprehensive monitoring and control over cloud environments.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Aviatrix Egress Security & Policy Enforcement would likely have limited the attacker's ability to exfiltrate data by enforcing strict egress controls and monitoring outbound traffic.

Impact (Mitigations)

Aviatrix Zero Trust CNSF would likely have limited the overall impact of the incident by reducing the attacker's ability to access and exfiltrate sensitive data through strict segmentation and access controls.

Impact at a Glance

Affected Business Functions

  • Email Communications
  • Document Management
  • Collaboration Tools
  • VoIP Services
Operational Disruption

Estimated downtime: 14 days

Financial Impact

Estimated loss: $500,000

Data Exposure

Potential exposure of sensitive corporate communications, internal documents, and confidential business information.

Recommended Actions

  • Implement Zero Trust Segmentation to restrict lateral movement within Microsoft 365 services.
  • Enforce Egress Security & Policy Enforcement to monitor and control outbound data transfers.
  • Utilize Multicloud Visibility & Control to detect and respond to anomalous activities across cloud services.
  • Deploy Threat Detection & Anomaly Response mechanisms to identify and mitigate suspicious behaviors.
  • Regularly audit and update safe-sender lists to prevent phishing emails from bypassing security filters.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image