The Greatness Phishing-as-a-Service platform has extended its capabilities from simple credential theft to advanced adversary-in-the-middle and device-code phishing techniques, compromising Microsoft 365 accounts with persistence exceeding two weeks. According to research published by ZeroBEC on BleepingComputer on August 4, 2026, operators bypassed email security filters by impersonating RingCentral, exploiting the fact that the SaaS platform's domain was present on victims' corporate whitelists. The combination of technical bypass and social engineering represents a significant evolution in the service's operational maturity, active since mid-2022.
- Greatness achieved Spam Confidence Level -1 on Microsoft Exchange by spoofing RingCentral, already on corporate whitelists, bypassing normal filtering stages.
- Emails included a fraudulent "verified by organization's safe-sender list" banner to bolster credibility in users' eyes.
- The dual MFA compromise mechanism combines AiTM flows for real-time token interception and device-code phishing for alternative scenarios.
- Post-compromise, attackers conducted multi-service enumeration via Microsoft Graph API with persistent access exceeding two weeks in some cases.
The Whitelist Trick: Why the Filter Doesn't Filter
The core of the attack lies in abusing the email trust architecture of target organizations. Greatness operators sent emails from the spoofed sender service@ringcentral[.]com, hosted on unknown IONOS servers, with failed SPF and DMARC and no DKIM signature. According to the cited dossier, these emails were nevertheless accepted by filtering systems because RingCentral appeared on corporate whitelists.
The result was a Spam Confidence Level value of -1 on Microsoft Exchange. SCL -1 indicates the message was treated as internal or explicitly trusted, skipping standard antispam and antimalware checks. ZeroBEC explains that "the tactic achieved a Spam Confidence Level of -1 on Microsoft Exchange, allowing it to bypass normal email filtering stages." This is not a Microsoft product vulnerability, but the expected behavior of a system configured to trust a domain without additional verification.
To complete the bypass, emails included a fraudulent banner declaring the communication "verified by organization's safe-sender list." This social engineering element reinforced the perception of legitimacy, reducing the likelihood users would report the anomaly even with contextual red flags present.
From Click to MFA Compromise: AiTM and Device-Code Phishing
Links in the emails led to Greatness infrastructure with dynamic routing to two distinct attack flows. The first, based on adversary-in-the-middle techniques, intercepted MFA-approved authentication tokens during the user's legitimate session. The second used device-code phishing, an alternative technique that does not require direct credential entry on a cloned portal but exploits the device authorization flow to gain access.
Post-token acquisition, operators replicated sessions from commercial VPS and VPNs, a pattern indicative of deliberate anonymization measures. This access architecture reflects operational maturity distinguishing Greatness from less structured phishing services active in the criminal landscape.
Graph API Enumeration and Persistence Beyond Two Weeks
Once access was established, attackers conducted reconnaissance and exfiltration via Microsoft Graph API. Enumeration covered: Outlook mailboxes, Teams, SharePoint sites, OneDrive stores, contact directories, calendars, and registered tenant applications. This multi-service access profile indicates a goal of deep reconnaissance rather than isolated credential theft.
Persistence exceeded two weeks in some analyzed cases. This duration, combined with systematic enumeration, supports the assessment that account compromise represents an initial phase for subsequent operations — Business Email Compromise, sensitive data theft, or pivoting to other corporate systems — rather than an end in itself. The dossier does not specify the nature of exposed data or any post-compromise extortion.
The RingCentral Breach Context: Hypothesized Correlation, Not Proven
On July 28, 2026, RingCentral published a security bulletin regarding a data breach attributed to threat actor ShinyHunters, stating that "the incident affected data for a limited portion of RingCentral customers, and we are communicating directly with affected customers." ZeroBEC hypothesized that Greatness operators may have obtained a valid target list — users of the RingCentral platform — from this incident.
The connection, however, is not confirmable at this stage. The dossier explicitly states the uncertainty of this correlation, and no infrastructure overlaps technically linking the Greatness campaign to the ShinyHunters breach have emerged. The hypothesis remains plausible but unverified, and the use of the RingCentral domain as a spoofing vector does not necessarily require access to breach data: impersonation of widely used SaaS platforms is a common phishing tactic independent of specific targeting sources.
What to Do Now
Organizations using Microsoft 365 must review whitelist and safe-sender list configurations to reduce the attack surface exposed by this vector. Three specific actions emerge from the documented case:
Remove RingCentral and other generic SaaS domains from unconditional whitelists. The SCL -1 achieved by Greatness stems directly from the presence of ringcentral[.]com in corporate safe-sender lists. Assigning implicit trust to public service domains bypasses SPF, DMARC, and DKIM even when these fail, as occurred with unknown IONOS servers.
Implement additional verification for senders with failed SPF/DMARC even when whitelisted. The dossier documents that Greatness emails had failed SPF and DMARC and no DKIM signature, yet were accepted anyway. Exchange configurations must maintain authentication checks independent of the trusted sender list.
Monitor access from commercial VPS and VPNs to Microsoft 365 tenants. Post-compromise, Greatness operators replicated tokens from these infrastructures. Detection of active Graph API sessions from IPs associated with commercial hosting providers represents a relevant behavioral indicator, especially when combined with multi-service enumeration.
Check for "verified by organization's safe-sender list" banners in incoming emails. This social engineering element was generated by attackers, not Microsoft systems. Its presence in external emails indicates active content manipulation and should trigger manual review.
"ZeroBEC comments that it's likely that cybercriminals using Greatness got a list of valid targets, users of the RingCentral platform, from that incident, though a connection cannot be confidently made."
Greatness's evolution from mid-2022 to today illustrates a common trajectory in the PhaaS market: the progressive addition of MFA bypass techniques, integration of more refined social engineering, and extension of post-compromise persistence. The specific case of SCL -1 achieved through whitelist abuse represents a qualitative leap, however, because it exploits not a technical vulnerability but a managerial security assumption: that a legitimate domain remains legitimate even when impersonated.
Organizations maintaining extensive whitelists of SaaS domains are exposed to this vector regardless of the maturity of their email authentication controls. The assessment emerging from the dossier is that email channel security cannot rely on static trust lists in a context where impersonation of known platforms has become operationally trivial for structured criminal services.
Frequently Asked Questions
Is SCL -1 a Microsoft Exchange vulnerability?
No. SCL -1 is the expected result of corporate whitelist configuration in Exchange: when a sender is on the safe-sender list, the system assigns this value to bypass filters. The problem lies in the whitelist configuration, not the product.
Does device-code phishing require MFA?
The device-code phishing flow exploits device authorization mechanisms that can bypass traditional authentication procedures. According to the dossier, this mechanism represents one of two vectors used by Greatness, alternative to the AiTM flow.
Can victims identify the attack from logs?
The dossier does not specify published indicators of compromise or detectable log patterns. The source does not document specific anomalous signs beyond post-compromise access from commercial VPS/VPNs.
Information is based on the cited source and current as of publication.
Sources
- https://www.bleepingcomputer.com/news/security/phishing-service-spoofs-ringcentral-to-steal-microsoft-365-accounts/
- https://www.bleepingcomputer.com/
- https://www.bleepingcomputer.com/tutorials/
- https://www.bleepingcomputer.com/download/
- https://deals.bleepingcomputer.com/