Nigeria Arrests Developers Behind RaccoonO365 Phishing Scheme

Three Suspects Arrested in Nigeria for Running RaccoonO365 Phishing Scheme Targeting Microsoft 365 Users Worldwide

  • Three suspects were arrested in Nigeria for running phishing attacks linked to the RaccoonO365 phishing-as-a-service scheme targeting major corporations.
  • The principal suspect, identified as Okitipi Samuel, sold phishing links via Telegram and used stolen email credentials to host fake login portals.
  • RaccoonO365 is a toolkit enabling attackers to steal Microsoft 365 credentials through fake login pages, impacting at least 5,000 users across 94 countries since July 2024.
  • The arrests followed a joint investigation involving Nigeria’s police, Microsoft, and the FBI.
  • Lawsuits are underway against individuals and groups operating similar phishing services that facilitate large-scale cybercrimes.

Authorities in Nigeria have arrested three individuals suspected of involvement in high-profile internet fraud connected to phishing attacks on corporations. The arrests are part of efforts to dismantle the RaccoonO365 phishing-as-a-service (PhaaS) operation, which targets Microsoft 365 users.

- Advertisement -

The Nigeria Police Force National Cybercrime Centre (NPF–NCCC), working with Microsoft and the Federal Bureau of Investigation (FBI), identified Okitipi Samuel, also known as Moses Felix, as the main developer of the phishing tools. According to the NPF, “he operated a Telegram channel through which phishing links were sold in exchange for cryptocurrency and hosted fraudulent login portals on Cloudflare using stolen or fraudulently obtained email credentials.” Following search operations, devices including laptops and mobile phones linked to the scheme were seized. The other two suspects have no involvement in developing or operating the phishing service.

RaccoonO365 is recognized as a financially motivated threat group providing a phishing toolkit to harvest credentials by serving fake Microsoft 365 login pages. Microsoft monitors this group under the name Storm-2246. In September 2025, Microsoft and Cloudflare took down 338 domains tied to RaccoonO365. The phishing infrastructure is reported to have compromised at least 5,000 Microsoft accounts from 94 countries since July 2024.

The NPF reported that the fake portals were designed to steal user login details to illicitly access email platforms used by corporate, financial, and educational organizations. This led to incidents of unauthorized access from phishing messages impersonating legitimate Microsoft authentication pages between January and September 2025. These breaches caused business email compromise, data leaks, and financial losses across multiple regions.

Additionally, a civil lawsuit filed by Microsoft and Health-ISAC in September accused Joshua Ogundipe and others of operating a cybercriminal network that sells and distributes the RaccoonO365 phishing kit. The stolen credentials fuel further cybercrimes such as financial fraud, Ransomware attacks, and intellectual property theft.

- Advertisement -

Separately, Google has filed legal action against operators of another phishing-as-a-service platform named Darcula, led by Chinese national Yucheng Chang and others. This suit seeks court orders to seize the group’s servers after a large-scale smishing campaign. This follows an earlier lawsuit by Google against Hackers linked to the Lighthouse PhaaS, which has affected over 1 million users in 120 countries. Additional information on the Darcula case was reported by NBC News.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Jeffy Yu, Crypto Founder Who Faked Death, Allegedly Dies

Crypto founder Jeffy Yu is alleged to have committed suicide in Roseville on New...

Unstable Ground: Looming U.S. Crypto Rules May Lack Legal Backing

SEC Chairman Paul Atkins is pushing for crypto rules but warns they need a...

Apple Stock Forms Technical Buy Point, Nears Breakout

Apple stock (AAPL) is forming a technical buy point and nearing a breakout, with...

LSEG to launch Digital Securities Sandbox for tokenization

London Stock Exchange Group (LSEG) plans to launch a Digital Securities Sandbox (DSD) this...

Tesla China Sales Slide in Jan., Exports Jump 71%

Tesla's retail sales in China plunged to 18,485 vehicles in January, their lowest monthly...

Must Read

14 Ways On How to Make Money with Cryptocurrency

Many people want to make money with cryptocurrency because they have heard the success stories of people who became millionaires from zero.If you...
🔥 #AD Get 20% OFF any new 12 month hosting plan from Hostinger. Click here!