How is this happening?
Attackers are impersonating RingCentral with fake voicemail and performance-review emails aimed at real RingCentral users. The messages direct recipients to fraudulent Microsoft 365 sign-in pages designed to capture credentials, MFA-approved session tokens, or device-code authentication.
What is the weakness?
The largest risk is treating trusted brands or domains as automatically safe. Attackers can exploit broad safe-sender and allowlist rules even when the message fails normal SPF, DKIM, or DMARC checks. A convincing branded notification and an unexpected MFA prompt can also lead users to approve an attacker’s sign-in request.
Users should:
- Verify the source of any unexpected voicemail, document, performance-review, and MFA requests through a known contact method before clicking or approving.
i4DM offers Password Manager, EMFA, and Cybersecurity Awareness Training that assist with:
- Phishing Simulations: Running realistic attack scenarios to train users to recognize sophisticated lures.
- Strong Authentication: Implementing phishing-resistant MFA and password-less methods to protect against token theft.
- Advanced Defenses: We strengthen Microsoft 365 sign-in protections, including phishing-resistant MFA where appropriate, Conditional Access, and user-verification procedures.
- Monitoring: Our team monitors suspicious Microsoft 365 sign-ins from hosting providers, VPN infrastructure, and unfamiliar locations. We review OAuth consent, Microsoft Graph activity, registered applications, and access to sensitive Microsoft 365 services.
- Safe Sender: I4DM helps review safe sender lists and replace blanket domain exclusions with rules that require valid email authentication.
- Call today for more details – 410-846-9138