Focusing on RingCentral-Impersonation Phishing Targeting Microsoft 365. What you should do to stay safe.

How is this happening? 

Attackers are impersonating RingCentral with fake voicemail and performance-review emails aimed at real RingCentral users. The messages direct recipients to fraudulent Microsoft 365 sign-in pages designed to capture credentials, MFA-approved session tokens, or device-code authentication.

What is the weakness? 

The largest risk is treating trusted brands or domains as automatically safe. Attackers can exploit broad safe-sender and allowlist rules even when the message fails normal SPF, DKIM, or DMARC checks. A convincing branded notification and an unexpected MFA prompt can also lead users to approve an attacker’s sign-in request.

Users should: 

  • Verify the source of any unexpected voicemail, document, performance-review, and MFA requests through a known contact method before clicking or approving. 

i4DM offers Password Manager, EMFA, and Cybersecurity Awareness Training that assist with: 

  • Phishing Simulations: Running realistic attack scenarios to train users to recognize sophisticated lures.
  • Strong Authentication: Implementing phishing-resistant MFA and password-less methods to protect against token theft. 
  • Advanced Defenses: We strengthen Microsoft 365 sign-in protections, including phishing-resistant MFA where appropriate, Conditional Access, and user-verification procedures.
  • Monitoring: Our team monitors suspicious Microsoft 365 sign-ins from hosting providers, VPN infrastructure, and unfamiliar locations. We review OAuth consent, Microsoft Graph activity, registered applications, and access to sensitive Microsoft 365 services.
  • Safe Sender: I4DM helps review safe sender lists and replace blanket domain exclusions with rules that require valid email authentication.
  • Call today for more details – 410-846-9138

Click here for a full description.

Recent Posts