Urgent.News

the world's headlines, one feed

Editions

Tech

Microsoft 365 users hit by phishing scheme posing as RingCentral emails

Operators of the Greatness PhaaS scam are targeting Microsoft 365 accounts by spoofing RingCentral.

Microsoft 365 users hit by phishing scheme posing as RingCentral emails

Microsoft 365 users are facing a new phishing scheme that aims to steal their accounts, even if they have multi-factor authentication (MFA) enabled. Attackers are spoofing RingCentral emails, following a data breach at the hands of the ShinyHunters hackers. The emails impersonate RingCentral, appearing to be sent from the company itself, but are actually coming from an unknown mail server and failing SPF and DMARC checks.

Clicking on the emails redirects users to a fake Microsoft 365 login page, allowing the attackers to capture MFA-approved authentication tokens and bypass the login process. Once inside the victim's account, the cybercriminals can access Outlook mailboxes, Teams conversations, SharePoint sites, OneDrive files, contacts, calendars, and registered applications via Microsoft Graph.

The Greatness platform, which is responsible for this attack, is selling access on Telegram for a monthly fee of $289 and has been active for at least four years, targeting users in various regions including the US, UK, Australia, Canada, and South Africa.

Written by urgent.news from TechRadar's reporting — not their text. Machine-written — it may contain errors, so check the original before relying on it.

Read the original at techradar.com →

More in Tech