← Home
CYBERSECURITY

Microsoft 365 Users Targeted in Sophisticated Phishing Attack

August 11, 2026 Daniel Cross

Phishing Service Targets Major Online Platforms

A new phishing campaign is actively compromising Microsoft 365 accounts. Cybercriminals are impersonating RingCentral communications to trick users. This scheme, run by the GreatnessPhaaS (Phishing-as-a-Service) group, aims to steal login credentials.

The attackers are using increasingly sophisticated methods. They are evolving their tactics to bypass common security measures. This includes multi-factor authentication (MFA), a critical layer of protection.

The Greatness PhaaS operation is not limited to Microsoft 365. It also targets other widely used online services. These include i Cloud, Yahoo, and Google Workspace accounts. The group continuously refines its techniques to overcome security protocols.

How Are These Attacks Bypassing Security Measures?

Their strategy involves spoofing legitimate company communications. This makes the phishing emails appear trustworthy to unsuspecting recipients. Once a user clicks a malicious link, their credentials can be compromised. This allows attackers to gain unauthorized access to accounts.

The attackers are employing advanced evasion techniques. They exploit vulnerabilities in how some MFA systems are implemented. This allows them to intercept or bypass the second authentication step. Users should always be wary of unexpected login prompts or verification requests.

The success of these attacks highlights a growing threat. Even with MFA enabled, users must remain vigilant. Organizations need to continuously update their security defenses. User education is also crucial in preventing these breaches.

Compromised accounts can lead to significant data loss and financial fraud. Businesses and individuals should implement robust security practices. Regularly changing passwords and scrutinizing all emails are vital steps.

Frequently Asked Questions

What is PhaaS? PhaaS stands for Phishing-as-a-Service. It is a subscription-based model where cybercriminals offer phishing tools and infrastructure to other attackers, making it easier to launch sophisticated campaigns.

How do these attacks bypass multi-factor authentication (MFA)? These advanced phishing kits can sometimes intercept the one-time codes or session tokens generated by MFA. This allows attackers to gain access even after a user has entered their second authentication factor.

What should I do if I receive a suspicious email? Do not click on any links or open attachments in suspicious emails. Verify the sender's identity through an alternative method, such as calling the company directly, before taking any action.

Read full article on Tech Site News →