Criminals impersonate popular communication platform to trick users into surrendering Microsoft 365 login credentials.
Security researchers have uncovered a new scam where criminals pretend to be RingCentral, a widely-used business communication platform, to trick employees into handing over their Microsoft 365 passwords. The fraudsters send messages that look official and urgent, claiming there's a problem that requires immediate action. When users click the links and enter their credentials, the attackers gain complete access to corporate email accounts, files, and sensitive business data.
This isn't just a minor annoyance—it's a serious threat that affects thousands of companies relying on these platforms for daily operations. The technique is called phishing, and it works because the fake messages are designed to look nearly identical to legitimate communications employees receive regularly.
Think of your email account like the front door to your house. Once someone has the key, they can enter whenever they want, steal your belongings, and even pretend to be you when talking to your neighbors. The same principle applies here.
When attackers gain access to a business email account, they can:
The problem is amplified because RingCentral is so common in business settings. Employees trust communications appearing to come from this platform, making them less suspicious when they receive these fake alerts.
Separately, network equipment manufacturer TP-Link has released security patches for 15 different weaknesses in their Omada devices—machines that manage network connections for organizations. These flaws could potentially be combined like puzzle pieces to allow attackers to take complete control of a company's network infrastructure. When these types of equipment vulnerabilities exist alongside phishing attacks, the risk becomes even greater.
Verify before you act. If you receive an urgent message from RingCentral asking you to confirm your password, don't click links in the email. Instead, go directly to the official website by typing the address yourself in your browser or calling the support number from your records.
Watch for warning signs. Legitimate companies rarely ask for passwords through email. Phishing messages often contain spelling errors, unusual sender addresses, or links that don't quite match the official domain.
Enable additional security layers. Use multi-factor authentication (an extra verification step beyond just your password) on all important accounts, especially business email and collaboration tools.
Keep systems updated. If your organization uses TP-Link network devices, ensure your IT team applies the latest security patches immediately.
Report suspicious messages. Forward potential phishing attempts to your IT security team rather than deleting them. This helps protect others in your organization.
By staying alert and following these basic security practices, you significantly reduce the chances that your account becomes the gateway for a larger organizational breach.
Want to understand the technology behind this story? ITVedas has beginner-friendly guides on every IT topic.
Explore IT Chapters →