Even Trusted Emails Can Be Phishing Scams
Cybercriminals are getting smarter, and they’re taking advantage of the companies and services we already trust.
A recent phishing campaign targeting Microsoft 365 users is a prime example. Attackers have been impersonating RingCentral, sending fake voicemail and notification emails designed to trick employees into clicking malicious links and surrendering their Microsoft 365 credentials. (Source: BleepingComputer)
What Does the Attack Look Like?
The emails are designed to look like legitimate RingCentral notifications. In some cases, they even include a fake security banner claiming that the sender has been verified by the organization’s safe-sender list.
Because many organizations add RingCentral to their trusted or allowlisted sender lists, these malicious emails can easily slip past standard security defenses.
What Does This Mean for Your Employees?
It means that “it came from a company we use” is no longer enough to make an email trustworthy.
Your team should be especially cautious with unexpected messages regarding:
- New voicemails or missed calls
- Password or account notifications
- Documents requiring review
- Performance reviews or HR notifications
- Billing or payment requests
If an email asks you to click a link and sign in to Microsoft 365, stop and verify it first. Instead of clicking the link, open the application directly through your normal login or contact your IT team.
A Good Rule to Remember
Trusted company ≠ trusted email.
Cybercriminals know which vendors your organization uses and are increasingly weaponizing those familiar names to make phishing attacks more convincing. Security tools are an essential layer of protection, but an alert and cautious employee remains one of your strongest defenses.
When something doesn’t feel right, don’t click. Verify first.
The Bottom Line
This is an impersonation attack, not a RingCentral breach. Attackers rely on your familiarity with trusted vendors to bypass caution.
Because a compromised Microsoft 365 account gives cybercriminals the keys to your emails, files, and core systems, a single click can put your entire organization at risk. When in doubt, always verify.


