Nigeria Arrests Developers Behind RaccoonO365 Phishing Scheme

Three Suspects Arrested in Nigeria for Running RaccoonO365 Phishing Scheme Targeting Microsoft 365 Users Worldwide

  • Three suspects were arrested in Nigeria for running phishing attacks linked to the RaccoonO365 phishing-as-a-service scheme targeting major corporations.
  • The principal suspect, identified as Okitipi Samuel, sold phishing links via Telegram and used stolen email credentials to host fake login portals.
  • RaccoonO365 is a toolkit enabling attackers to steal Microsoft 365 credentials through fake login pages, impacting at least 5,000 users across 94 countries since July 2024.
  • The arrests followed a joint investigation involving Nigeria’s police, Microsoft, and the FBI.
  • Lawsuits are underway against individuals and groups operating similar phishing services that facilitate large-scale cybercrimes.

Authorities in Nigeria have arrested three individuals suspected of involvement in high-profile internet fraud connected to phishing attacks on corporations. The arrests are part of efforts to dismantle the RaccoonO365 phishing-as-a-service (PhaaS) operation, which targets Microsoft 365 users.

- Advertisement -

The Nigeria Police Force National Cybercrime Centre (NPF–NCCC), working with Microsoft and the Federal Bureau of Investigation (FBI), identified Okitipi Samuel, also known as Moses Felix, as the main developer of the phishing tools. According to the NPF, “he operated a Telegram channel through which phishing links were sold in exchange for cryptocurrency and hosted fraudulent login portals on Cloudflare using stolen or fraudulently obtained email credentials.” Following search operations, devices including laptops and mobile phones linked to the scheme were seized. The other two suspects have no involvement in developing or operating the phishing service.

RaccoonO365 is recognized as a financially motivated threat group providing a phishing toolkit to harvest credentials by serving fake Microsoft 365 login pages. Microsoft monitors this group under the name Storm-2246. In September 2025, Microsoft and Cloudflare took down 338 domains tied to RaccoonO365. The phishing infrastructure is reported to have compromised at least 5,000 Microsoft accounts from 94 countries since July 2024.

The NPF reported that the fake portals were designed to steal user login details to illicitly access email platforms used by corporate, financial, and educational organizations. This led to incidents of unauthorized access from phishing messages impersonating legitimate Microsoft authentication pages between January and September 2025. These breaches caused business email compromise, data leaks, and financial losses across multiple regions.

Additionally, a civil lawsuit filed by Microsoft and Health-ISAC in September accused Joshua Ogundipe and others of operating a cybercriminal network that sells and distributes the RaccoonO365 phishing kit. The stolen credentials fuel further cybercrimes such as financial fraud, Ransomware attacks, and intellectual property theft.

- Advertisement -

Separately, Google has filed legal action against operators of another phishing-as-a-service platform named Darcula, led by Chinese national Yucheng Chang and others. This suit seeks court orders to seize the group’s servers after a large-scale smishing campaign. This follows an earlier lawsuit by Google against Hackers linked to the Lighthouse PhaaS, which has affected over 1 million users in 120 countries. Additional information on the Darcula case was reported by NBC News.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

XRP Eyes Rally as ETFs and Buy Signal Boost 2026 Hopes Surge

Ripple settled its US lawsuit in 2025, helping XRP reach a $3.65 all-time high...

Bitfinex Hacker Ilya Lichtenstein Freed Early via First Step

Ilya Lichtenstein was released from prison after serving 14 months of a five-year sentence...

Waymo’s 2026 Expansion Could Drive Big Gains for GOOGL Surge

Alphabet rallied more than 60% in 2025 and enters 2026 with investor optimism tied...

Tesla shares slip as Q4 deliveries deemed largely neutral US

Tesla delivered 418,227 vehicles in Q4, slightly below the 422,850 company-polled consensus and last...

Institutions Pour In: 2026 Poised to Ignite ETH Value Rise!!

Ethereum insiders say 2026 could trigger significant ETH value growth as institutions increase on-chain...
- Advertisement -

Must Read

Top 9 Most Legit Bitcoin Faucets

Bitcoin faucets are platforms where you can earn Bitcoin free. Some other faucet apps and websites allow users to receive different cryptocurrencies for free....
Bitcoin (BTC) $ 89,913.00 1.92%
Ethereum (ETH) $ 3,122.71 4.50%
XRP (XRP) $ 1.99 6.52%
Bittensor (TAO) $ 245.42 8.02%
Polkadot (DOT) $ 2.12 6.40%
Cardano (ADA) $ 0.388114 8.36%
Chainlink (LINK) $ 13.28 6.06%
Hyperliquid (HYPE) $ 24.58 0.76%
Monero (XMR) $ 419.74 0.04%
Hedera (HBAR) $ 0.120309 6.40%
Toncoin (TON) $ 1.81 6.80%