Security reports say a phishing-as-a-service (PhaaS) operation known as “Greatness” is targeting Microsoft 365 users by sending messages that spoof RingCentral. The scheme is described as expanding beyond basic credential theft to include adversary-in-the-middle tactics and device-code phishing, which are designed to compromise accounts by capturing authentication flows rather than only asking for usernames and passwords.
Both outlets report that the campaign uses “RingCentral” as a lure, sending emails that appear intended for or related to communication services. Microsoft 365 account targeting is emphasized, with attackers aiming to gain unauthorized access to victims’ Microsoft accounts.
TechRadar and Bleeping Computer also frame the activity as part of the Greatness platform’s broader evolution, noting that its methods now include multiple phishing approaches intended to increase success rates against modern authentication. The reports focus on the impersonation of RingCentral and the targeting of Microsoft 365 accounts through phishing infrastructure associated with the Greatness PhaaS operation.