Fake RingCentral Emails Target Microsoft 365 Accounts | Sync Up
A voicemail notification in your inbox might seem routine, but a new phishing campaign is using those familiar alerts to steal access to Microsoft 365 accounts. Find out how the attack works and what can help stop it as we sit down and sync up with Rocket IT’s weekly technology update.
In this episode, you’ll hear more about:
- How spoofed RingCentral messages are being used in Microsoft 365 phishing attacks.
- Why some of these emails were able to bypass normal filtering.
- How attackers can capture access even after MFA is completed.
- What compromised Microsoft 365 accounts can expose.
- What users and organizations can do to reduce the risk of similar phishing attacks.
Video Transcript
Security researchers at ZeroBEC recently uncovered a phishing campaign built around fake RingCentral notifications. RingCentral is a business communications platform commonly used for calling, messaging, and voicemail, and in this campaign, attackers impersonated the service to make their emails look more trustworthy.
Some of the messages appeared to be voicemail alerts, while others claimed a performance review was ready. Each encouraged the recipient to click a button to open the message. But there was something especially concerning about how these emails reached the inbox.
The organization investigated by ZeroBEC was an actual RingCentral customer and had added the company’s domain to a safe-sender list. That setting was meant to keep legitimate RingCentral messages from being filtered as spam. Attackers took advantage of that trust.
The phishing emails were not actually sent by RingCentral. In fact, they failed the standard checks used to verify where an email really came from. But because the RingCentral domain had been marked as trusted, those failures were overridden and the messages were still delivered. The emails even included a fake banner claiming the sender had been verified by the organization’s safe-sender list, giving the message another layer of credibility at first glance. Clicking the link led into a phishing platform called Greatness.
Greatness is what is known as phishing-as-a-service. Instead of creating an attack from scratch, criminals can pay for a ready-made platform that provides the tools and templates needed to launch phishing campaigns. ZeroBEC found that Greatness is being sold through Telegram for $289 per month and includes templates for voicemail messages, document sharing, QR codes, and other common lures.
Once someone followed the fake RingCentral message, the attack could lead to a Microsoft 365 sign-in experience that looked convincing enough to include the organization’s real branding. And this is where the attack goes beyond simply stealing a password.
One technique used by Greatness can sit between the person signing in and the real Microsoft 365 service. The person enters a password and completes multifactor authentication just as expected, but the attacker captures the approved authentication token in the process.
Researchers observed stolen access being used to explore Outlook mailboxes, Teams conversations, SharePoint sites, OneDrive files, contacts, calendars, and other Microsoft 365 resources. In some cases, that access remained active for more than two weeks.
This story serves as useful reminder that a familiar sender name, a trusted-looking banner, or even a normal Microsoft sign-in screen should not be the only signals used to decide whether a message is legitimate. Unexpected voicemail notifications, performance reviews, shared documents, and similar messages deserve an extra look before opening a link. If something feels unusual, go directly to the service or application instead of using the button inside the email.
For organizations, this campaign also highlights the importance of reviewing safe-sender rules. Rocket IT recommends avoiding broad exceptions that automatically trust an entire vendor domain and instead requiring messages to pass the normal authentication checks that confirm they actually came from that vendor. And if an account may have been compromised, changing the password alone may not be enough. Because attacks like this can capture an already-approved authentication token, active sessions and tokens may also need to be revoked before access is fully removed.
The goal isn’t to distrust every voicemail notification that hits the inbox. It is to recognize that attackers are getting better at borrowing the trust people already place in familiar tools, brands, and security controls. And if your organization needs help reviewing email protections or strengthening Microsoft 365 security, contact Rocket IT using the link in this video’s description. And to stay up to date on trending technology news, hit that subscribe button and the bell to catch us on next week’s episode of Sync Up with Rocket IT.
Related Posts
Subscribe to Rocket IT's Newsletter
Stay up to date on trending technology news and important updates.
Find out if Rocket IT is the right partner for your team
Claim a free consultation with a technology expert.