{"id":679,"date":"2026-08-07T16:37:15","date_gmt":"2026-08-07T11:07:15","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=679"},"modified":"2026-08-18T16:39:57","modified_gmt":"2026-08-18T11:09:57","slug":"greatness-phaas-uses-ringcentral-trust-to-steal-microsoft-365-tokens","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/greatness-phaas-uses-ringcentral-trust-to-steal-microsoft-365-tokens\/","title":{"rendered":"Greatness PhaaS Uses RingCentral Trust to Steal Microsoft 365 Tokens"},"content":{"rendered":"<p>Cybercriminals continue to refine phishing techniques, and the latest Greatness phishing campaign demonstrates how attackers can compromise Microsoft 365 accounts without relying solely on stolen passwords. By spoofing RingCentral notifications and abusing trusted sender configurations, attackers trick users into authentic-looking Microsoft login flows that capture valid authentication tokens.<\/p>\n<p>The campaign highlights a growing enterprise security challenge. Traditional email filtering and MFA are no longer sufficient when attackers steal session tokens or exploit legitimate authentication workflows. Organizations must secure identities, devices, and cloud workloads together to reduce exposure.<\/p>\n<p><center>    \t\t<!-- button style scb6aaa006dc095ba618bc1777be3a12f2a -->\r\n    \t\t<style>\r\n    \t\t\t.scb6aaa006dc095ba618bc1777be3a12f2a, a.scb6aaa006dc095ba618bc1777be3a12f2a{\r\n    \t\t\t\tcolor: #fff;\r\n    \t\t\t\tbackground-color: ;\r\n    \t\t\t}\r\n    \t\t\t.scb6aaa006dc095ba618bc1777be3a12f2a:hover, a.scb6aaa006dc095ba618bc1777be3a12f2a:hover{\r\n    \t\t\t\t    \t\t\t\tbackground-color: #323232;\r\n    \t\t\t}\r\n    \t\t<\/style>\r\n    \t\t<a href=\"https:\/\/www.hexnode.com\/uem\/\" class=\"ht-shortcodes-button scb6aaa006dc095ba618bc1777be3a12f2a  hn-cta__blogs--inline-button \" id=\"\" style=\"\" >\r\n    \t\tStrengthen Identity Security with Hexnode<\/a>\r\n    \t\t<\/center><\/p>\n<h2>How the Greatness phishing campaign works<\/h2>\n<p>Researchers recently observed the Greatness phishing-as-a-service (PhaaS) platform expanding beyond credential theft into AiTM phishing and device-code phishing attacks targeting Microsoft 365 users.<\/p>\n<p>The attackers distributed phishing emails disguised as:<\/p>\n<ul>\n<li>RingCentral voicemail notifications<\/li>\n<li>Employee performance review alerts<\/li>\n<\/ul>\n<p>Although the emails failed SPF and DMARC validation and lacked DKIM signatures, many still reached users because RingCentral domains had been broadly trusted in recipient-side allowlists. Microsoft Exchange assigned the messages a Spam Confidence Level (SCL) of -1, indicating they were bypassed by safe-sender logic despite failing standard email authentication checks. This allowed malicious emails to evade recipient-side filtering.<\/p>\n<p>Once victims clicked the embedded links, they were redirected to attacker-controlled infrastructure supporting multiple Microsoft 365 phishing techniques.<\/p>\n<table>\n<thead>\n<tr>\n<th>Attack stage<\/th>\n<th>Description<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Initial lure<\/td>\n<td>Fake RingCentral notifications<\/td>\n<\/tr>\n<tr>\n<td>Email bypass<\/td>\n<td>Trusted sender logic accepted unauthenticated mail<\/td>\n<\/tr>\n<tr>\n<td>Credential stage<\/td>\n<td>Victims redirected to Microsoft-themed phishing pages<\/td>\n<\/tr>\n<tr>\n<td>Account compromise<\/td>\n<td>Authentication tokens captured using AiTM or device-code flows<\/td>\n<\/tr>\n<tr>\n<td>Post-compromise<\/td>\n<td>Microsoft Graph used to access organizational data<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>AiTM phishing and device-code phishing enable MFA bypass<\/h2>\n<p>Unlike traditional phishing, AiTM phishing places an attacker-controlled proxy between the user and Microsoft. The victim completes a legitimate authentication flow, including <a href=\"https:\/\/www.hexnode.com\/blogs\/reinforcing-cybersecurity-with-multi-factor-authentication-mfa\/\">MFA,<\/a> while the attacker captures the authenticated session token.<\/p>\n<p>Instead of stealing only passwords, attackers obtain reusable authentication tokens that provide immediate access to Microsoft 365 resources.<\/p>\n<p>The campaign also employed device-code phishing, which abuses Microsoft&#8217;s OAuth 2.0 Device Authorization Grant workflow. This authentication flow is designed for devices with limited input capabilities, allowing users to authorize a session by entering a device code on Microsoft&#8217;s sign-in page. Attackers exploit this legitimate process by tricking victims into entering attacker-generated device codes, unknowingly granting the attacker access to their Microsoft 365 session.<\/p>\n<p>Both approaches enable an effective MFA bypass because attackers leverage valid authentication rather than attempting to defeat the MFA mechanism itself.<\/p>\n<p>After gaining access, attackers used Microsoft Graph APIs to enumerate:<\/p>\n<ul>\n<li>Outlook mailboxes<\/li>\n<li>Teams conversations<\/li>\n<li>SharePoint sites<\/li>\n<li>OneDrive files<\/li>\n<li>Contacts<\/li>\n<li>Calendars<\/li>\n<li>Registered Microsoft 365 applications<\/li>\n<li>OAuth permissions<\/li>\n<\/ul>\n<p>This broad visibility enables data theft, business email compromise, and additional lateral movement throughout Microsoft 365 environments.<\/p>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-.jpg?format=webp\" class=\"resource-box__image\" alt=\"cybersecurity kit\" loading=\"lazy\" srcset=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-.jpg?format=webp 960w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit--300x225.jpg?format=webp 300w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit--768x576.jpg?format=webp 768w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit--133x100.jpg?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"cybersecurity kit\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured Resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Cybersecurity kit\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Access essential cybersecurity resources to strengthen security, reduce risk, and improve cyber resilience.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/resource-kits\/cybersecurity-kit\/'>\n                            Download the Resource Kit\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<h2>How Hexnode helps reduce identity-based phishing risks<\/h2>\n<p>Modern phishing campaigns demonstrate that identity security and device security cannot operate in isolation. While Microsoft Entra ID helps protect identities through authentication, Conditional Access, and sign-in risk analysis, organizations also need trusted endpoint management to ensure only secure, compliant devices can access corporate resources. Together, identity controls and device posture provide stronger protection against modern token-based attacks.<\/p>\n<p><a href=\"https:\/\/www.hexnode.com\/xdr\/\">Hexnode XDR<\/a> correlates behavioral signals across endpoints, enriches alerts with device and UEM context, maps detected attack chains to <a href=\"https:\/\/www.hexnode.com\/blogs\/mitre-attack-framework\/\">MITRE ATT&amp;CK<\/a>, and allows analysts to investigate historical process and endpoint-event data.<\/p>\n<p>These correlated endpoint signals help analysts investigate detected threats and take containment actions such as isolating devices, terminating malicious processes, or quarantining files.<\/p>\n<p>Hexnode UEM complements identity security by enforcing security controls on managed devices, including:<\/p>\n<ul>\n<li>Secure browser configuration policies<\/li>\n<li>Device compliance enforcement<\/li>\n<li>Trusted device access controls<\/li>\n<li>Endpoint security baselines<\/li>\n<\/ul>\n<p>Organizations can also strengthen Microsoft 365 protection by allowing access only from trusted, compliant, and managed devices.<\/p>\n<p>Hexnode UEM can integrate with Microsoft Entra <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-conditional-access\/\">Conditional Access<\/a> to control access to enterprise resources based on Hexnode device compliance, while Office 365 access can also be restricted to enrolled devices through supported Conditional Access configurations.<\/p>\n<h2>Best practices to defend against Greatness phishing<\/h2>\n<p>Security teams should treat token theft with the same urgency as credential theft.<\/p>\n<p>Recommended defensive measures include:<\/p>\n<ul>\n<li>Audit safe-sender and email allowlists regularly.<\/li>\n<li>Replace broad domain allowlisting with authenticated-mail validation rules.<\/li>\n<li>Monitor Microsoft 365 sign-ins originating from hosting providers, VPS infrastructure, or VPN services.<\/li>\n<li>Investigate unusual MFA-approved sessions.<\/li>\n<li>Revoke active authentication tokens immediately after suspected compromise.<\/li>\n<li>Review OAuth consent grants and Microsoft Graph activity.<\/li>\n<li>Limit Microsoft 365 access to compliant, managed devices.<\/li>\n<li>Continuously monitor endpoint and identity telemetry for post-compromise behavior.<\/li>\n<\/ul>\n<p>These layered controls reduce the impact of phishing campaigns that target authentication tokens instead of passwords.<\/p>\n<div class=\"faq-section-wrapper\" itemscope itemtype=\"https:\/\/schema.org\/FAQPage\"><h2 class=\"faq-main-title\">FAQs<\/h2><div class=\"faq-items\"><div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">What is Greatness phishing?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Greatness phishing is a phishing-as-a-service (PhaaS) platform that targets Microsoft 365 users. It supports advanced techniques such as AiTM phishing and device-code phishing to steal authentication tokens instead of only usernames and passwords.<\/p>\n<\/div><\/div><\/div> <div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">What is device-code phishing?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Device-code phishing abuses Microsoft&#8217;s legitimate device authorization process. Attackers convince users to enter a valid device code on Microsoft&#8217;s login page, unknowingly granting attackers access to their Microsoft 365 accounts.<\/p>\n<\/div><\/div><\/div> <div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">How does AiTM phishing bypass MFA?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>AiTM phishing captures authenticated session tokens after users complete legitimate MFA. Since attackers reuse valid authentication tokens rather than passwords, they can effectively achieve an MFA bypass without breaking the MFA mechanism itself.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Why should organizations monitor Microsoft Graph activity?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Attackers often use Microsoft Graph after compromising Microsoft 365 accounts to enumerate mailboxes, Teams data, SharePoint sites, OneDrive files, contacts, calendars, and application permissions. Monitoring Graph activity helps identify abnormal post-compromise behavior early.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">How does device compliance help reduce the risk of stolen authentication tokens?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Microsoft Entra Conditional Access can use Hexnode device compliance as a condition for granting access to Microsoft 365 resources. If an attacker attempts to reuse a stolen authentication token from an unmanaged or non-compliant device, Conditional Access policies can deny access because the device does not satisfy the organization&#8217;s compliance requirements. While device compliance does not prevent token theft itself, it helps limit the usefulness of stolen tokens by enforcing access only from trusted, managed devices.<\/p>\n<\/div><\/div><\/div><\/div><\/div>\n<h3>Conclusion<\/h3>\n<p>The latest Greatness phishing campaign demonstrates how phishing attacks continue to evolve beyond credential theft. By combining AiTM phishing, device-code phishing, and trusted sender abuse, attackers can obtain Microsoft 365 authentication tokens and maintain access even after MFA succeeds.<\/p>\n<p>Organizations should strengthen email trust policies, monitor token-based attacks, secure Microsoft 365 identities, and combine identity security with endpoint visibility. A layered security approach that integrates IAM, endpoint management, and XDR provides stronger protection against modern phishing campaigns.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Protect Microsoft 365 Identities<\/h5><p>Detect token theft, enforce trusted device access, and strengthen identity security with Hexnode UEM and XDR.<\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Start Your Free Trial! <\/a><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Cybercriminals continue to refine phishing techniques, and the latest Greatness phishing campaign demonstrates how attackers&#8230;<\/p>\n","protected":false},"author":6,"featured_media":683,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[10,16],"class_list":["post-679","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-phishing","category-windows","product_category-identity-provider","tab_group-identity-and-phishing"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Greatness Phishing Targets Microsoft 365<\/title>\n<meta name=\"description\" content=\"Learn how Greatness phishing bypasses MFA to steal Microsoft 365 tokens and how Hexnode helps reduce enterprise risk.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/greatness-phaas-uses-ringcentral-trust-to-steal-microsoft-365-tokens\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Greatness Phishing Targets Microsoft 365\" \/>\n<meta property=\"og:description\" content=\"Learn how Greatness phishing bypasses MFA to steal Microsoft 365 tokens and how Hexnode helps reduce enterprise risk.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/greatness-phaas-uses-ringcentral-trust-to-steal-microsoft-365-tokens\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-07T11:07:15+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-18T11:09:57+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Greatness-PhaaS-Uses-RingCentral-Trust-to-Steal-Microsoft-365-Tokens.png?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Lily Anne\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Lily Anne\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/greatness-phaas-uses-ringcentral-trust-to-steal-microsoft-365-tokens\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/greatness-phaas-uses-ringcentral-trust-to-steal-microsoft-365-tokens\\\/\"},\"author\":{\"name\":\"Lily Anne\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/072b33718ec5df7cb7dbb9bae93044fa\"},\"headline\":\"Greatness PhaaS Uses RingCentral Trust to Steal Microsoft 365 Tokens\",\"datePublished\":\"2026-08-07T11:07:15+00:00\",\"dateModified\":\"2026-08-18T11:09:57+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/greatness-phaas-uses-ringcentral-trust-to-steal-microsoft-365-tokens\\\/\"},\"wordCount\":1145,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/greatness-phaas-uses-ringcentral-trust-to-steal-microsoft-365-tokens\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Greatness-PhaaS-Uses-RingCentral-Trust-to-Steal-Microsoft-365-Tokens.png?format=webp\",\"articleSection\":[\"Phishing\",\"Windows\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/greatness-phaas-uses-ringcentral-trust-to-steal-microsoft-365-tokens\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/greatness-phaas-uses-ringcentral-trust-to-steal-microsoft-365-tokens\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/greatness-phaas-uses-ringcentral-trust-to-steal-microsoft-365-tokens\\\/\",\"name\":\"Greatness Phishing Targets Microsoft 365\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/greatness-phaas-uses-ringcentral-trust-to-steal-microsoft-365-tokens\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/greatness-phaas-uses-ringcentral-trust-to-steal-microsoft-365-tokens\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Greatness-PhaaS-Uses-RingCentral-Trust-to-Steal-Microsoft-365-Tokens.png?format=webp\",\"datePublished\":\"2026-08-07T11:07:15+00:00\",\"dateModified\":\"2026-08-18T11:09:57+00:00\",\"description\":\"Learn how Greatness phishing bypasses MFA to steal Microsoft 365 tokens and how Hexnode helps reduce enterprise risk.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/greatness-phaas-uses-ringcentral-trust-to-steal-microsoft-365-tokens\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/greatness-phaas-uses-ringcentral-trust-to-steal-microsoft-365-tokens\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/greatness-phaas-uses-ringcentral-trust-to-steal-microsoft-365-tokens\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Greatness-PhaaS-Uses-RingCentral-Trust-to-Steal-Microsoft-365-Tokens.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Greatness-PhaaS-Uses-RingCentral-Trust-to-Steal-Microsoft-365-Tokens.png?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"Greatness PhaaS Uses RingCentral Trust to Steal Microsoft 365 Tokens\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/greatness-phaas-uses-ringcentral-trust-to-steal-microsoft-365-tokens\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Greatness PhaaS Uses RingCentral Trust to Steal Microsoft 365 Tokens\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/072b33718ec5df7cb7dbb9bae93044fa\",\"name\":\"Lily Anne\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"caption\":\"Lily Anne\"},\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/lily-anne\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Greatness Phishing Targets Microsoft 365","description":"Learn how Greatness phishing bypasses MFA to steal Microsoft 365 tokens and how Hexnode helps reduce enterprise risk.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/greatness-phaas-uses-ringcentral-trust-to-steal-microsoft-365-tokens\/","og_locale":"en_US","og_type":"article","og_title":"Greatness Phishing Targets Microsoft 365","og_description":"Learn how Greatness phishing bypasses MFA to steal Microsoft 365 tokens and how Hexnode helps reduce enterprise risk.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/greatness-phaas-uses-ringcentral-trust-to-steal-microsoft-365-tokens\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-08-07T11:07:15+00:00","article_modified_time":"2026-08-18T11:09:57+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Greatness-PhaaS-Uses-RingCentral-Trust-to-Steal-Microsoft-365-Tokens.png?format=webp","type":"image\/png"}],"author":"Lily Anne","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Lily Anne","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/greatness-phaas-uses-ringcentral-trust-to-steal-microsoft-365-tokens\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/greatness-phaas-uses-ringcentral-trust-to-steal-microsoft-365-tokens\/"},"author":{"name":"Lily Anne","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/072b33718ec5df7cb7dbb9bae93044fa"},"headline":"Greatness PhaaS Uses RingCentral Trust to Steal Microsoft 365 Tokens","datePublished":"2026-08-07T11:07:15+00:00","dateModified":"2026-08-18T11:09:57+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/greatness-phaas-uses-ringcentral-trust-to-steal-microsoft-365-tokens\/"},"wordCount":1145,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/greatness-phaas-uses-ringcentral-trust-to-steal-microsoft-365-tokens\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Greatness-PhaaS-Uses-RingCentral-Trust-to-Steal-Microsoft-365-Tokens.png?format=webp","articleSection":["Phishing","Windows"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/greatness-phaas-uses-ringcentral-trust-to-steal-microsoft-365-tokens\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/greatness-phaas-uses-ringcentral-trust-to-steal-microsoft-365-tokens\/","url":"https:\/\/www.hexnode.com\/threat-watch\/greatness-phaas-uses-ringcentral-trust-to-steal-microsoft-365-tokens\/","name":"Greatness Phishing Targets Microsoft 365","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/greatness-phaas-uses-ringcentral-trust-to-steal-microsoft-365-tokens\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/greatness-phaas-uses-ringcentral-trust-to-steal-microsoft-365-tokens\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Greatness-PhaaS-Uses-RingCentral-Trust-to-Steal-Microsoft-365-Tokens.png?format=webp","datePublished":"2026-08-07T11:07:15+00:00","dateModified":"2026-08-18T11:09:57+00:00","description":"Learn how Greatness phishing bypasses MFA to steal Microsoft 365 tokens and how Hexnode helps reduce enterprise risk.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/greatness-phaas-uses-ringcentral-trust-to-steal-microsoft-365-tokens\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/greatness-phaas-uses-ringcentral-trust-to-steal-microsoft-365-tokens\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/greatness-phaas-uses-ringcentral-trust-to-steal-microsoft-365-tokens\/#primaryimage","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Greatness-PhaaS-Uses-RingCentral-Trust-to-Steal-Microsoft-365-Tokens.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Greatness-PhaaS-Uses-RingCentral-Trust-to-Steal-Microsoft-365-Tokens.png?format=webp","width":1340,"height":700,"caption":"Greatness PhaaS Uses RingCentral Trust to Steal Microsoft 365 Tokens"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/greatness-phaas-uses-ringcentral-trust-to-steal-microsoft-365-tokens\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"Greatness PhaaS Uses RingCentral Trust to Steal Microsoft 365 Tokens"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/072b33718ec5df7cb7dbb9bae93044fa","name":"Lily Anne","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","caption":"Lily Anne"},"url":"https:\/\/www.hexnode.com\/threat-watch\/author\/lily-anne\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/679","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=679"}],"version-history":[{"count":1,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/679\/revisions"}],"predecessor-version":[{"id":685,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/679\/revisions\/685"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/683"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=679"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=679"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}