BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Microsoft, Cloudflare Seize 338 Domains Tied to RaccoonO365 Phishing

Microsoft and Cloudflare Dismantle Global RaccoonO365 Phishing Operation, Seize 338 Domains and Identify Suspected Leader

  • Microsoft and Cloudflare seized 338 domains linked to the phishing group RaccoonO365.
  • The group stole over 5,000 Microsoft 365 credentials from victims in 94 countries since July 2024.
  • RaccoonO365 operated as a phishing-as-a-service toolkit sold on a subscription model to cybercriminals.
  • The service targeted major companies, used advanced evasion methods, and advertised upgrades after the takedown.
  • Authorities identified a Nigerian individual as the suspected leader, and law enforcement referrals have followed.

Microsoft and Cloudflare disrupted the activities of the cybercriminal group RaccoonO365 by taking control of 338 websites the group used for phishing schemes. The action began as a coordinated global operation under a court order from the Southern District of New York in early September 2025.

- Advertisement -

According to Microsoft’s Digital Crimes Unit, RaccoonO365 used its phishing service to steal more than 5,000 Microsoft 365 usernames and passwords from individuals in 94 countries since July 2024. The group offered its phishing toolkit to buyers on a subscription basis, charging $355 for 30 days or $999 for 90 days.

“Using a court order granted by the Southern District of New York, the DCU seized 338 websites associated with the popular service, disrupting the operation’s technical infrastructure and cutting off criminals’ access to victims,” said Steven Masada, assistant general counsel at DCU. Cloudflare banned the identified domains, added warning pages, disabled associated scripts, and suspended user accounts between September 2 and September 8, 2025. The company said this strategy was aimed at “a proactive, large-scale disruption aimed at dismantling the actor’s operational infrastructure on our platform.”

Microsoft tracked the group as Storm-2246. RaccoonO365 allowed even inexperienced users to carry out large-scale phishing and credential theft by mimicking trusted companies such as Microsoft, DocuSign, SharePoint, and Adobe in fake emails. These emails led victims to lookalike sites designed to steal their login information. The service included features to circumvent multi-factor authentication and offered tools like Cloudflare Turnstile CAPTCHAs to block automated analysis and open access only for intended victims.

The group also promoted new features, such as an AI-powered service named RaccoonO365 AI-MailCheck, to increase the reach and success of its attacks. The operators said they hosted the tools on “bulletproof” servers to avoid shutdowns and advertised primarily on a Telegram channel with about 850 members.

- Advertisement -

Authorities have identified Joshua Ogundipe, a Nigerian national, as the suspected leader of the RaccoonO365 operation, based on a security mistake that made a cryptocurrency wallet visible. Microsoft believes the group sold between 100 and 200 subscriptions and collected at least $100,000 in cryptocurrency. A criminal referral has been sent to international law enforcement.

Since the takedown, the threat actors have told their clients to stop using old links, offering a free subscription extension after switching to the new plan. Cloudflare emphasized that disrupting the group would make continued phishing activities more expensive and difficult to conduct.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

SideCopy Targets Afghan Finance With Xeno RAT

The Pakistan-aligned SideCopy group deployed a sophisticated spear-phishing campaign codenamed Operation XENOFISCAL against Afghanistan's...

Solana Dips Below $80 as Macro Woes Spark Market Jitters

Solana (SOL) has dropped below $80, declining 2.5% daily and 5.4% weekly according to...

Musk defends SpaceX valuation citing Tesla’s IPO rise

Elon Musk defended SpaceX's high valuation by pointing to Tesla's growth from a $1.7...

Robinhood Enters Canada via $180M WonderFi Deal

Robinhood has entered the Canadian market by completing a $180 million stock acquisition of...

Dashlane Brute-Force Attack Hits Fewer Than 20 Users

Dashlane disclosed a brute-force attack where encrypted vaults for fewer than 20 personal plan...

Must Read

What Is Bcrypt Password Hashing Function?

KEY TAKEAWAYSBcrypt is a password hashing function that transforms plain passwords into unique alphanumeric sequences.It is a one-way process, ensuring that passwords cannot be...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading