Phishing‑as‑a‑Service Spoofs RingCentral to Harvest Microsoft 365 Credentials
What Happened — The Greatness PhaaS platform began using a spoofed RingCentral sender address to deliver phishing emails that bypassed Exchange filters and captured Microsoft 365 authentication tokens via adversary‑in‑the‑middle (AiTM) and device‑code flows. Victims’ accounts were accessed for up to two weeks, exposing Outlook, Teams, SharePoint, OneDrive and other data.
Why It Matters for Compliance & Audit Readiness
- Demonstrates a failure of access‑control monitoring and MFA token protection that SOC 2 CC6 (Logical Access) expects to be continuously evidenced.
- Highlights the need for documented security‑awareness training and phishing‑simulation programs to satisfy the SOC 2 CC7 (Security Awareness) requirement.
- Shows why maintaining up‑to‑date email‑authentication (SPF/DKIM/DMARC) and whitelist governance is essential evidence for the “System Operations” trust principle.
Who Is Affected – SaaS providers and enterprises that rely on Microsoft 365, RingCentral, or similar cloud communication tools (technology, professional services, finance, education, etc.).
Recommended Actions – Review and tighten email‑authentication policies; enforce MFA with conditional access that blocks token replay; implement continuous security‑awareness training and phishing‑simulation; monitor for anomalous token usage and maintain audit‑ready logs of access‑control events. Source: BleepingComputer
Technical Notes – Attack vector: phishing email spoofing RingCentral (failed SPF/DMARC, no DKIM) → AiTM or device‑code flow → MFA token capture → token replay via VPS/VPN. No CVE involved. Source: same