Nigeria Arrests Developers Behind RaccoonO365 Phishing Scheme

Three Suspects Arrested in Nigeria for Running RaccoonO365 Phishing Scheme Targeting Microsoft 365 Users Worldwide

  • Three suspects were arrested in Nigeria for running phishing attacks linked to the RaccoonO365 phishing-as-a-service scheme targeting major corporations.
  • The principal suspect, identified as Okitipi Samuel, sold phishing links via Telegram and used stolen email credentials to host fake login portals.
  • RaccoonO365 is a toolkit enabling attackers to steal Microsoft 365 credentials through fake login pages, impacting at least 5,000 users across 94 countries since July 2024.
  • The arrests followed a joint investigation involving Nigeria’s police, Microsoft, and the FBI.
  • Lawsuits are underway against individuals and groups operating similar phishing services that facilitate large-scale cybercrimes.

Authorities in Nigeria have arrested three individuals suspected of involvement in high-profile internet fraud connected to phishing attacks on corporations. The arrests are part of efforts to dismantle the RaccoonO365 phishing-as-a-service (PhaaS) operation, which targets Microsoft 365 users.

- Advertisement -

The Nigeria Police Force National Cybercrime Centre (NPF–NCCC), working with Microsoft and the Federal Bureau of Investigation (FBI), identified Okitipi Samuel, also known as Moses Felix, as the main developer of the phishing tools. According to the NPF, “he operated a Telegram channel through which phishing links were sold in exchange for cryptocurrency and hosted fraudulent login portals on Cloudflare using stolen or fraudulently obtained email credentials.” Following search operations, devices including laptops and mobile phones linked to the scheme were seized. The other two suspects have no involvement in developing or operating the phishing service.

RaccoonO365 is recognized as a financially motivated threat group providing a phishing toolkit to harvest credentials by serving fake Microsoft 365 login pages. Microsoft monitors this group under the name Storm-2246. In September 2025, Microsoft and Cloudflare took down 338 domains tied to RaccoonO365. The phishing infrastructure is reported to have compromised at least 5,000 Microsoft accounts from 94 countries since July 2024.

The NPF reported that the fake portals were designed to steal user login details to illicitly access email platforms used by corporate, financial, and educational organizations. This led to incidents of unauthorized access from phishing messages impersonating legitimate Microsoft authentication pages between January and September 2025. These breaches caused business email compromise, data leaks, and financial losses across multiple regions.

Additionally, a civil lawsuit filed by Microsoft and Health-ISAC in September accused Joshua Ogundipe and others of operating a cybercriminal network that sells and distributes the RaccoonO365 phishing kit. The stolen credentials fuel further cybercrimes such as financial fraud, Ransomware attacks, and intellectual property theft.

- Advertisement -

Separately, Google has filed legal action against operators of another phishing-as-a-service platform named Darcula, led by Chinese national Yucheng Chang and others. This suit seeks court orders to seize the group’s servers after a large-scale smishing campaign. This follows an earlier lawsuit by Google against Hackers linked to the Lighthouse PhaaS, which has affected over 1 million users in 120 countries. Additional information on the Darcula case was reported by NBC News.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Soldier used military secrets for $150K crypto bets.

An Israeli reserve soldier and a civilian accomplice face charges for allegedly using military...

BitGo, 21Shares Expand ETF Staking & Custody Partnership

BitGo and 21Shares have expanded their partnership to provide custody, trading, and staking services...

North Korean Hackers Use Google’s Gemini AI for Cyber Recon

Google's threat intelligence team observed the North Korean hacking group UNC2970 using the generative...

Binance SAFU Fund Now Holds $1 Billion in Bitcoin

Binance has purchased $305 million in Bitcoin for its user protection fund, bringing its...

Jeffy Yu, Crypto Founder Who Faked Death, Allegedly Dies

Crypto founder Jeffy Yu is alleged to have committed suicide in Roseville on New...

Must Read

The 13 Best Crypto Advertising Networks to Grow Your Project

TABLE OF CONTENTSWhy Traditional Ad Networks (Like Google & Facebook) Fail CryptoQuick-View Comparison TableHow to Choose the Right Crypto Ad Network for Your ProjectBest...
🔥 #AD Get 20% OFF any new 12 month hosting plan from Hostinger. Click here!