{
  "id": 178663,
  "title": "Microsoft 365 users hit by phishing scheme posing as RingCentral emails",
  "url": "https://urgent.news/2026/08/05/microsoft-365-users-hit-by-phishing-scheme-posing-as-ringcentral",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-05T13:05:00.000Z",
  "source": {
    "name": "TechRadar",
    "slug": "techradar",
    "url": "https://www.techradar.com/pro/security/microsoft-365-users-hit-by-phishing-scheme-posing-as-ringcentral-emails"
  },
  "original_language": "en",
  "account": "Microsoft 365 users are facing a new phishing scheme that aims to steal their accounts, even if they have multi-factor authentication (MFA) enabled. Attackers are spoofing RingCentral emails, following a data breach at the hands of the ShinyHunters hackers. The emails impersonate RingCentral, appearing to be sent from the company itself, but are actually coming from an unknown mail server and failing SPF and DMARC checks. Clicking on the emails redirects users to a fake Microsoft 365 login page, allowing the attackers to capture MFA-approved authentication tokens and bypass the login process. Once inside the victim's account, the cybercriminals can access Outlook mailboxes, Teams conversations, SharePoint sites, OneDrive files, contacts, calendars, and registered applications via Microsoft Graph. The Greatness platform, which is responsible for this attack, is selling access on Telegram for a monthly fee of $289 and has been active for at least four years, targeting users in various regions including the US, UK, Australia, Canada, and South Africa.",
  "summary": "Operators of the Greatness PhaaS scam are targeting Microsoft 365 accounts by spoofing RingCentral.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}