Filed under: Cybersecurity — Phishing — August 2026
What happened
Researchers caught a commercial phishing kit called “Greatness” — sold for $289 a month on Telegram — running a campaign that spoofs RingCentral voicemail and performance-review notification emails. The messages fail standard email authentication checks but still land in inboxes because RingCentral is on many companies’ trusted-sender allow lists, and the email itself falsely claims to be “verified” by that same list. Clicking the button routes victims through a fake Microsoft sign-in that either captures an already-approved login session or talks them into approving a “device code” sign-in — either way, the attacker ends up with a working session that never had to beat a password or MFA prompt. Researchers found stolen sessions still logging in successfully more than two weeks later.
Why it matters to your business
If your business uses RingCentral for phones or voicemail — common among Phoenix small businesses — or has simply allow-listed it in your email filters, this campaign is built to slip past your spam protection entirely. Once an attacker has a live session in someone’s mailbox, they can read invoices and client files, redirect payments, and send convincing messages to your customers and vendors as if they came from your own staff. Because the kit is sold to anyone with $289, expect copies of this trick wearing other trusted brand names next.
What to do this week
In the Microsoft 365 Defender portal (security.microsoft.com), go to Email & collaboration > Policies & rules > Threat policies > Anti-spam policies and check for any “allowed sender/domain” entries for RingCentral or other vendors that skip standard filtering — tighten or remove blanket allow rules like that. In the Microsoft Entra admin center (entra.microsoft.com), go to Protection > Conditional Access and, if you haven’t already, restrict the “device code” authentication flow to only the accounts that genuinely need it. Tell staff plainly: a “verified sender” banner inside an email proves nothing, and no one should approve a device sign-in code they didn’t personally request. Spot-check Entra sign-in logs for sessions from unfamiliar locations that have stayed active for days.
The bigger picture
Phishing kits keep getting better at hiding behind trusted brand names to slip past technical filters, which makes a skeptical, trained employee your last and most reliable line of defense. — Phishing Attacks: Why SMBs Are Prime Targets and How to Fight Back
Not sure your email filters would catch a trick like this? Book a free consult — https://micro1tech.com/contact/