Direct answer
RingCentral Greatness phishing UCaaS identity proof packet: what buyers need to know
BleepingComputer reported on August 4, 2026 that the Greatness phishing-as-a-service platform spoofed RingCentral emails to target Microsoft 365 accounts through adversary-in-the-middle and device-code phishing. TechRadar independently covered the ZeroBEC-reported campaign on August 5, including MFA-approved token capture and Microsoft Graph access. Xcitium Threat Labs described the same pattern as a $289-a-month kit exploiting trusted sender treatment. VoIP buyers should treat the story as UCaaS identity proof: voicemail and phone-service notifications are not trustworthy unless sender authentication, allowlists, MFA sessions, Graph activity, and recovery controls are tested together.
This brief cites the source announcement and translates the event into a buyer framework. Verify current vendor terms before changing phone, messaging, or AI routing.
What happened
- BleepingComputer reported that Greatness has expanded from credential phishing to adversary-in-the-middle and device-code phishing against Microsoft 365 accounts.
- The campaign used fake voicemail and performance-review notifications that claimed to come from [email protected] and targeted actual users of the communications platform.
- The report said the messages failed SPF and DMARC checks and lacked DKIM, yet were accepted because RingCentral was whitelisted, with Microsoft Exchange assigning an SCL of -1.
- Clicking the embedded button routed users to Greatness infrastructure that captured MFA-approved authentication tokens or used a device-code phishing flow.
- Post-compromise activity included replayed tokens and Microsoft Graph enumeration of Outlook, Teams, SharePoint, OneDrive, contacts, calendars, and registered applications.
- RingCentral's July 28 security bulletin said a limited portion of customer data was affected by a separate incident; reporting described a possible targeting-list connection but did not confirm it.
Why this is trending
- The story has current coverage across BleepingComputer, TechRadar, Xcitium, and related security outlets within the same week.
- It turns a familiar UCaaS workflow, a voicemail or service notification, into a cloud-identity and Microsoft 365 session risk.
- It shows that email authentication can fail operationally when safe-sender rules override SPF, DKIM, and DMARC results.
- The $289-per-month phishing-kit framing makes the threat feel operationally scalable rather than a one-off campaign.
- The buyer impact crosses phone systems, messaging, email security, identity, SaaS administration, and incident recovery.
The VoIP Stack Index take
A VoIP buyer should not evaluate UCaaS security only by uptime, encryption, or MFA settings. Ask for a UCaaS Identity Proof Packet showing how vendor notifications are authenticated, which domains are allowlisted, how voicemail lures are flagged, whether MFA-approved sessions can be detected, what Microsoft Graph data a stolen token can reach, and how quickly sessions, OAuth grants, mailbox rules, and user notices can be remediated.
UCaaS Identity Proof Packet
A VoIP and UCaaS buyer framework for validating trusted communications-platform emails, voicemail lures, safe-sender exclusions, MFA token exposure, Microsoft Graph blast radius, hunt evidence, and recovery control.
What buyers should do next
Audit UCaaS and collaboration vendor safe-sender entries, transport rules, mail-flow bypasses, and domain allowlists.
Require trusted vendor notifications to pass SPF, DKIM, and DMARC instead of relying on blanket domain trust.
Publish examples of legitimate voicemail, fax, recording, and service-notification messages for users and helpdesk teams.
Hunt for MFA-approved Microsoft 365 sign-ins from hosting providers, VPN infrastructure, unfamiliar devices, and new geographies.
Review Microsoft Graph activity, OAuth consents, mailbox rules, Teams access, SharePoint/OneDrive access, contacts, and calendars after suspected compromise.
Use the VoIP Stack Index AI-ready VoIP audit and VoIP cost calculator to turn UCaaS identity proof into procurement and renewal requirements.
Buyer bridge
Do the routing audit before buying the buzz.
The winning AI phone stack is the one that preserves context, controls fallback, and lets humans take over without making the customer repeat the story.
Run the AI-ready VoIP audit