UCaaS identity proof

RingCentral-Spoofed Phishing Made UCaaS Identity Proof a Buyer Test

The news hook is the August 2026 reporting on Greatness phishing-as-a-service campaigns that spoofed RingCentral emails to target Microsoft 365 users. BleepingComputer reported on August 4 that Greatness expanded from credential phishing into adversary-in-the-middle and device-code phishing, with fake voicemail and performance-review lures claiming to come from [email protected]. TechRadar independently covered the same ZeroBEC-reported campaign on August 5, including MFA-approved token capture and Microsoft Graph access to Outlook, Teams, SharePoint, OneDrive, contacts, calendars, and registered applications. Xcitium Threat Labs separately framed the campaign as a $289-a-month kit abusing trusted sender treatment. RingCentral's July 28 security bulletin said a limited portion of customer data was affected by a separate social-engineering incident; reporters treated any connection to the Greatness targeting list as plausible but not confirmed. The VoIP buyer issue is practical: UCaaS trust, voicemail notices, domain allowlists, Microsoft 365 sessions, MFA tokens, OAuth, Graph activity, and recovery proof all need validation before a trusted phone-service brand becomes a phishing shortcut.

Synthetic editorial image of telecom and identity-security analysts reviewing unbranded VoIP phones, network equipment, blurred login screens, and blank safe-sender paperwork.
Editorial image: synthetic representative telecom scene, not a photo of the named company or news event.

Direct answer

RingCentral Greatness phishing UCaaS identity proof packet: what buyers need to know

BleepingComputer reported on August 4, 2026 that the Greatness phishing-as-a-service platform spoofed RingCentral emails to target Microsoft 365 accounts through adversary-in-the-middle and device-code phishing. TechRadar independently covered the ZeroBEC-reported campaign on August 5, including MFA-approved token capture and Microsoft Graph access. Xcitium Threat Labs described the same pattern as a $289-a-month kit exploiting trusted sender treatment. VoIP buyers should treat the story as UCaaS identity proof: voicemail and phone-service notifications are not trustworthy unless sender authentication, allowlists, MFA sessions, Graph activity, and recovery controls are tested together.

Published 8/9/2026 News event 8/4/2026

This brief cites the source announcement and translates the event into a buyer framework. Verify current vendor terms before changing phone, messaging, or AI routing.

What happened

  • BleepingComputer reported that Greatness has expanded from credential phishing to adversary-in-the-middle and device-code phishing against Microsoft 365 accounts.
  • The campaign used fake voicemail and performance-review notifications that claimed to come from [email protected] and targeted actual users of the communications platform.
  • The report said the messages failed SPF and DMARC checks and lacked DKIM, yet were accepted because RingCentral was whitelisted, with Microsoft Exchange assigning an SCL of -1.
  • Clicking the embedded button routed users to Greatness infrastructure that captured MFA-approved authentication tokens or used a device-code phishing flow.
  • Post-compromise activity included replayed tokens and Microsoft Graph enumeration of Outlook, Teams, SharePoint, OneDrive, contacts, calendars, and registered applications.
  • RingCentral's July 28 security bulletin said a limited portion of customer data was affected by a separate incident; reporting described a possible targeting-list connection but did not confirm it.

Why this is trending

  • The story has current coverage across BleepingComputer, TechRadar, Xcitium, and related security outlets within the same week.
  • It turns a familiar UCaaS workflow, a voicemail or service notification, into a cloud-identity and Microsoft 365 session risk.
  • It shows that email authentication can fail operationally when safe-sender rules override SPF, DKIM, and DMARC results.
  • The $289-per-month phishing-kit framing makes the threat feel operationally scalable rather than a one-off campaign.
  • The buyer impact crosses phone systems, messaging, email security, identity, SaaS administration, and incident recovery.

The VoIP Stack Index take

A VoIP buyer should not evaluate UCaaS security only by uptime, encryption, or MFA settings. Ask for a UCaaS Identity Proof Packet showing how vendor notifications are authenticated, which domains are allowlisted, how voicemail lures are flagged, whether MFA-approved sessions can be detected, what Microsoft Graph data a stolen token can reach, and how quickly sessions, OAuth grants, mailbox rules, and user notices can be remediated.

UCaaS Identity Proof Packet

A VoIP and UCaaS buyer framework for validating trusted communications-platform emails, voicemail lures, safe-sender exclusions, MFA token exposure, Microsoft Graph blast radius, hunt evidence, and recovery control.

UCaaS Identity Proof Packet framework visual
Channel AI fit Human rule VoIP requirement
Sender trust rule Security tooling can compare claimed sender, envelope sender, SPF, DKIM, DMARC, transport rules, and safe-sender overrides. Administrators must decide which vendor domains are trusted only after authentication passes rather than by blanket allowlist. Safe-sender inventory, UCaaS notification domains, SPF/DKIM/DMARC evidence, transport-rule review, and exception owner.
Voicemail lure path Detection can group fake voicemail, recording, fax, performance-review, and meeting-notice lures that imitate phone-service workflows. Support and IT leaders must teach users how legitimate voicemail and service notices are delivered. Approved notice examples, user-facing warning copy, helpdesk script, reporting button, and phishing simulation evidence.
MFA token exposure Identity telemetry can flag MFA-approved sign-ins from hosting providers, VPNs, unfamiliar devices, and impossible travel. Security owners must treat token replay as an active session incident, not only a password problem. Session-risk rules, token revocation playbook, device-code controls, sign-in logs, and conditional-access evidence.
Graph blast radius SaaS monitoring can map which Outlook, Teams, SharePoint, OneDrive, contacts, calendars, and app permissions were touched. Business owners must decide which customer, legal, finance, and support records require notice or recovery. Microsoft Graph activity report, mailbox-rule audit, file-access list, registered-app review, and customer-impact notes.
Hunt evidence Threat hunting can match domains, Laravel cookies, redirects, proxy infrastructure, VPN sign-ins, OAuth consent, and user reports. Humans must validate indicators against the organization's real vendor-notification and sign-in patterns. IOC list, SIEM query, user-report queue, vendor-ticket reference, and analyst signoff.
Recovery control Automation can revoke active sessions, reset credentials, remove mailbox rules, disable risky apps, and open retest tasks. A named incident owner must control customer communications, user coaching, and closure evidence. Revocation log, credential rotation, OAuth cleanup, mailbox retest, customer notice decision, and closure report.

What buyers should do next

01

Audit UCaaS and collaboration vendor safe-sender entries, transport rules, mail-flow bypasses, and domain allowlists.

02

Require trusted vendor notifications to pass SPF, DKIM, and DMARC instead of relying on blanket domain trust.

03

Publish examples of legitimate voicemail, fax, recording, and service-notification messages for users and helpdesk teams.

04

Hunt for MFA-approved Microsoft 365 sign-ins from hosting providers, VPN infrastructure, unfamiliar devices, and new geographies.

05

Review Microsoft Graph activity, OAuth consents, mailbox rules, Teams access, SharePoint/OneDrive access, contacts, and calendars after suspected compromise.

06

Use the VoIP Stack Index AI-ready VoIP audit and VoIP cost calculator to turn UCaaS identity proof into procurement and renewal requirements.

Buyer bridge

Do the routing audit before buying the buzz.

The winning AI phone stack is the one that preserves context, controls fallback, and lets humans take over without making the customer repeat the story.

Run the AI-ready VoIP audit