Phishing‑as‑a‑Service Platform “Greatness” Uses Real Microsoft Login Pages to Harvest Credentials
What Happened — A new phishing‑as‑a‑service (PhaaS) offering called “Greatness” delivers attacks that present a genuine‑looking Microsoft sign‑in page. Victims enter their corporate credentials, giving attackers full access to email, files and other Office 365 resources without the need for a spoofed URL or malicious website.
Why It Matters for Compliance & Audit Readiness
- Demonstrates a failure of SOC 2 Access Control safeguards: the organization could not verify that only authorized users accessed cloud services.
- Highlights the need for continuous security awareness training and simulated phishing exercises to keep users vigilant against credential‑harvesting tactics that look legitimate.
- Provides a concrete scenario where audit evidence (login‑activity logs, MFA enforcement, training records) must be collected to prove the effectiveness of access‑control policies.
Who Is Affected — Primarily SaaS‑focused enterprises, cloud‑first tech firms, and any organization that relies on Microsoft 365 for email and collaboration.
Recommended Actions
- Map the incident to SOC 2 CC6.1 (Logical Access) and CC6.2 (User Authentication) controls; verify MFA is enforced for all privileged accounts.
- Deploy a phishing‑simulation program and track user click‑through rates as evidence of Security Awareness Training.
- Collect and retain Azure AD sign‑in logs and Conditional Access policy configurations for audit review.
Source: Smashing Security Podcast #480 – Graham Cluley
Technical Notes
- Attack vector: Phishing‑as‑a‑Service delivering a genuine Microsoft login page (no malicious URL required).
- No CVE; the threat relies on social engineering and credential reuse.
- Data at risk: corporate Microsoft 365 credentials, email content, SharePoint/OneDrive files.