Microsoft 365 users hit by phishing scheme posing as RingCentral emails
Security researchers at ZeroBEC say a phishing-as-a-service platform called Greatness has been used to spoof RingCentral emails and lure Microsoft 365 users to fake login pages that capture MFA-approved authentication tokens. Greatness is also reported to target iCloud, Yahoo, and Google Workspace accounts. The service is advertised on Telegram for $289 per month, per BleepingComputer.
How this was made

The 30-second read
Why it matters
The campaign aims to capture MFA-approved authentication tokens through attacker-controlled login pages, enabling access to Outlook, Teams, SharePoint, OneDrive, and apps via Microsoft Graph.
Market read
Traders may monitor Microsoft cloud security headlines, but the article lacks confirmed incident scope, financial impact, or Microsoft-specific actions.
What to watch
The article attributes activity to a PhaaS operator and notes victim counts are unknown; without confirmed breach scope or Microsoft’s response, trading impact may be muted.
Background
ZeroBEC reports a phishing-as-a-service platform, Greatness, evolving to target MFA-protected Microsoft 365 accounts via spoofed RingCentral emails.
Ticker impact
The article says phishing emails spoof RingCentral to trick Microsoft 365 users into fake logins that steal MFA-approved tokens.
Limited direct earnings impact expected, but heightened security incident risk could pressure sentiment around Microsoft’s cloud security posture.
The text describes an active credential-phishing campaign against Microsoft 365 accounts, but provides no confirmed scale, financial loss, or Microsoft-specific response.
Market effects
Cloud productivity and identity security vendors may see increased demand for MFA hardening, token protection, and phishing-resistant controls.
Primarily impacts users in the US, UK, Australia, Canada, and South Africa, but the operational risk is global for Microsoft 365.
If the campaign scales, it can reinforce broader enterprise concerns about identity compromise and token-based session hijacking.
Counterpoint
This is a common phishing pattern; unless Microsoft confirms a widespread incident or issues specific mitigations, the market may treat it as routine cybercrime rather than a Microsoft-specific problem.
Key entities
- productMicrosoft 365
Microsoft’s cloud productivity suite targeted by phishing designed to steal MFA-approved authentication tokens.
- companyRingCentral
Spoofed sender in the phishing emails; the article links the scheme to a prior RingCentral breach for email lists.
- researcherZeroBEC
Security researchers claiming observation of the Greatness PhaaS platform and its evolution to MFA token theft.
- threat_actor_platformGreatness
Phishing-as-a-service sold on Telegram for $289/month, used to target multiple cloud ecosystems.
- threat_actorShinyHunters
Referenced as the party behind a prior RingCentral breach that may have exfiltrated customer emails.




