HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Phishing‑as‑a‑Service Spoofs RingCentral to Harvest Microsoft 365 Credentials

Greatness PhaaS leveraged spoofed RingCentral emails to bypass Exchange filters and capture Microsoft 365 MFA tokens, exposing Outlook, Teams, SharePoint and OneDrive data. The incident underscores the importance of SOC 2 access‑control monitoring and security‑awareness training.

LiveThreat™ Intelligence · 📅 August 05, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
bleepingcomputer.com

Phishing‑as‑a‑Service Spoofs RingCentral to Harvest Microsoft 365 Credentials

What Happened — The Greatness PhaaS platform began using a spoofed RingCentral sender address to deliver phishing emails that bypassed Exchange filters and captured Microsoft 365 authentication tokens via adversary‑in‑the‑middle (AiTM) and device‑code flows. Victims’ accounts were accessed for up to two weeks, exposing Outlook, Teams, SharePoint, OneDrive and other data.

Why It Matters for Compliance & Audit Readiness

  • Demonstrates a failure of access‑control monitoring and MFA token protection that SOC 2 CC6 (Logical Access) expects to be continuously evidenced.
  • Highlights the need for documented security‑awareness training and phishing‑simulation programs to satisfy the SOC 2 CC7 (Security Awareness) requirement.
  • Shows why maintaining up‑to‑date email‑authentication (SPF/DKIM/DMARC) and whitelist governance is essential evidence for the “System Operations” trust principle.

Who Is Affected – SaaS providers and enterprises that rely on Microsoft 365, RingCentral, or similar cloud communication tools (technology, professional services, finance, education, etc.).

Recommended Actions – Review and tighten email‑authentication policies; enforce MFA with conditional access that blocks token replay; implement continuous security‑awareness training and phishing‑simulation; monitor for anomalous token usage and maintain audit‑ready logs of access‑control events. Source: BleepingComputer

Technical Notes – Attack vector: phishing email spoofing RingCentral (failed SPF/DMARC, no DKIM) → AiTM or device‑code flow → MFA token capture → token replay via VPS/VPN. No CVE involved. Source: same

📰 Original Source
https://www.bleepingcomputer.com/news/security/phishing-service-spoofs-ringcentral-to-steal-microsoft-365-accounts/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Phishing and social engineering are a people-and-policy problem.

The Verisq AI Trust Operations platform pairs Security Awareness Training with policy adoption tracking, so human-risk controls are documented and audit-ready.

Explore the Verisq AI Trust Operations platform →