Greatness Uses Microsoft Login Pages as Bait

Smashing Security episode 480 described two scams: Greatness, a phishing-as-a-service platform that uses a real Microsoft login page to steal access, and “Poison Claude,” which dangles discounted Anthropic Claude access to get victims to route traffic through a fraudulent service. Greatness works by sending people through the genuine Microsoft sign-in experience instead of a fake lookalike, so the usual tells — odd domains, bad branding, obvious typos — are missing. That can still hand attackers the credentials or session grant needed for mailbox, file, and tenant access, which makes the trust in the page itself the weak point. For organizations built around Microsoft 365 and Entra ID sign-ins, the exposure sits at the login layer: if the page is real but the operator is hostile, the normal phishing heuristics do not buy much protection. Poison Claude is a separate lure, but the same lesson applies — the pitch can look legitimate while the access path is not.

Part of the PlainSec briefing for 2026-08-13

Editions

Sources