Close Menu
  • Home
  • Cybercrime and Ransomware
  • Emerging Tech
  • Threat Intelligence
  • Expert Insights
  • Careers and Learning
  • Compliance

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

What's Hot

Exploit Attempts Targeting Super Forms, Elementor Pro RCE Flaws

September 4, 2026

Unisys deploys Microsoft AI for enhanced threat detection

September 3, 2026

Did ShinyHunters Breach ReliaQuest?

September 3, 2026
Facebook X (Twitter) Instagram
The CISO Brief
  • Home
  • Cybercrime and Ransomware
  • Emerging Tech
  • Threat Intelligence
  • Expert Insights
  • Careers and Learning
  • Compliance
Home » Microsoft Shuts Down RaccoonO365 Phishing Scam
Uncategorized

Microsoft Shuts Down RaccoonO365 Phishing Scam

Staff WriterBy Staff WriterSeptember 17, 2025No Comments5 Mins Read6 Views
Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest WhatsApp Email

Summary Points

  1. Collaboration Against Cybercrime: Microsoft and Cloudflare partnered to dismantle the phishing service "RaccoonO365," targeting a notorious cybercrime operation responsible for stealing Microsoft 365 credentials.

  2. Widespread Impact: RaccoonO365’s kits have compromised over 5,000 Microsoft accounts globally, targeting numerous organizations, including more than 20 healthcare entities in the U.S., posing significant public safety risks.

  3. Phishing-as-a-Service Model: This service enabled low-skill cybercriminals to conduct automated phishing attacks with ease, mimicking legitimate brands to deceive users into providing sensitive information.

  4. Enforcement Actions: Microsoft identified Nigerian mastermind Joshua Ogundipe, who is linked to at least $100,000 in cryptocurrency earnings, and submitted a criminal referral to international law enforcement.

[gptAs a technology journalist, write a short news story divided in two subheadings, at 12th grade reading level about ‘Microsoft Disrupts ‘RaccoonO365’ Phishing Service’in short sentences using transition words, in an informative and explanatory tone, from the perspective of an insightful Tech News Editor, ensure clarity, consistency, and accessibility. Use concise, factual language and avoid jargon that may confuse readers. Maintain a neutral yet engaging tone to provide balanced perspectives on practicality, possible widespread adoption, and contribution to the human journey. Avoid passive voice. The article should provide relatable insights based on the following information ‘

Microsoft and Cloudflare teamed up to take down a notorious phishing service known as “RaccoonO365,” the companies said this week.

In a blog post, Microsoft said its Digital Crimes Unit used a court order granted by the Southern District of New York to seize 338 websites associated with the service. In a blog post, Microsoft described RaccoonO365 as “the fastest-growing tool used by cybercriminals to steal Microsoft 365 usernames and passwords.”

The company, which tracks the gang behind the service as Storm-2246, offers subscription-based phishing kits. Phishing-as-a-service (PhaaS) kits have become an increasingly popular way for lower skill individuals that want to get into cybercrime.

“These let anyone — even those with little technical skill — steal Microsoft credentials by mimicking official Microsoft communications,” Steven Masada, blog post author and assistant general counsel of Microsoft’s Digital Crimes Unit, wrote. “To deceive users, RaccoonO365’s kits use Microsoft branding to make fraudulent emails, attachments, and websites appear legitimate, enticing recipients to open, click, and enter their information.”

RaccoonO365 Breaches Thousands

Masada explained that, since July 2024, RaccoonO365 kits have been used to steal at least 5,000 Microsoft credentials from 94 countries. He called the scope of Storm-2246’s reach a marker of “a troubling new phase of cybercrime where scams and threats are likely to multiply exponentially.”

Related:Self-Replicating ‘Shai-hulud’ Worm Targets NPM Packages

RaccoonO365 was used to target more than 2,300 organizations in the US as part of a tax-themed phishing campaign, and Microsoft said its kits were used to target at least 20 US healthcare organizations. “This puts public safety at risk, as RaccoonO365 phishing emails are often a precursor to malware and ransomware, which have severe consequences for hospitals,” Masada wrote.

A subscription allows a user to input up to 9,000 email addresses to target with automated phishing attacks, while advertising other services such as spam and email security filter bypassing as well as full infrastructure support. Interestingly, the service advertised that in order to steal Microsoft credentials, it leveraged Microsoft services such as Azure.

Screenshots showed an annual subscription fee of $600 as well as discounted options for 30- and 60-day licenses. Admins also started advertising a new AI-powered service titled “RaccoonO365 AI-MailCheck.”

According to a blog post from Cloudflare, which partnered with Microsoft to seize and take down attacker infrastructure, RaccoonO365 employed multiple phishing techniques such as impersonating DocuSign, SharePoint, Adobe, and Maersk in emails. Credential stealing functionality would be hidden in attached links or documents such as PDFs.

Related:‘Lies-in-the-Loop’ Attack Defeats AI Coding Agents

“RaccoonO365 phishing emails were crafted to impersonate trusted brands or organizations within the targeted company, using familiar workplace themes to exploit trust and create urgency. File names were designed to mimic routine communications — such as finance or HR documents, policy agreements, contracts, and invoices,” the blog post read. “In some cases, the emails went further, incorporating the recipient’s name into links or attachments to enhance credibility. This social engineering tactic increases the likelihood that users will click, believing the message is legitimate.”

Taking Down and Unmasking RaccoonO365

Microsoft’s Digital Crime Unit took the opportunity to identify and unmask Joshua Ogundipe, an individual based in Nigeria, as the mastermind behind RaccoonO365. Masada said he and his associates have received at least $100,000 USD in cryptocurrency, reflecting approximately 100 to 200 subscriptions, which Microsoft said was likely an underestimation of actual subscriptions sold.

The blog post painted a picture of an organized, company-like structure.

Related:‘K2 Think’ AI Model Jailbroken Mere Hours After Release

“Ogundipe and his associates each have specialized roles within the cybercriminal organization, and together they develop, and sell the service, while providing customer support to help other cybercriminals steal information from Microsoft users,” the blog post read. “To mask their criminal enterprise and evade detection, they registered Internet domains using fictitious names and physical addresses that are purportedly located in multiple cities and countries.”

And to the organizational piece, Masada noted that “an operational security lapse by the threat actors in which they inadvertently revealed a secret cryptocurrency wallet helped the DCU’s attribution and understanding of their operations.”

Microsoft has sent a criminal referral for Ogundipe to international law enforcement.

In its blog post, Cloudflare said it disrupted RaccoonO365 by teaming up with Microsoft and US law enforcement. The company used sign-up patterns to map attacker infrastructure before executing a three-day “rugpull” against the group earlier this month. Cloudflare “banned all identified domains, placed interstitial ‘phish warning’ pages in front of them, terminated the associated Workers scripts, and suspended the user accounts to prevent re-registration.”

Dark Reading contacted Microsoft for additional comment.

‘. Do not end the article by saying In Conclusion or In Summary. Do not include names or provide a placeholder of authors or source. Make Sure the subheadings are in between html tags of

[/gpt3]

Continue Your Tech Journey

Learn how the Internet of Things (IoT) is transforming everyday life.

Explore past and present digital transformations on the Internet Archive.

CyberRisk-V1

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleMicrosoft and Cloudflare Collapse Massive Phishing Empire
Next Article Transforming Web Security: 1Password and Perplexity Unite!
Avatar photo
Staff Writer
  • Website

John Marcelli is a staff writer for the CISO Brief, with a passion for exploring and writing about the ever-evolving world of technology. From emerging trends to in-depth reviews of the latest gadgets, John stays at the forefront of innovation, delivering engaging content that informs and inspires readers. When he's not writing, he enjoys experimenting with new tech tools and diving into the digital landscape.

Related Posts

Urgent: Court Software Breach Risks Exposure of SSNs and Confidential Data

September 3, 2026

Critical flaw exploited to steal nuclear records from Philippine research agency

August 28, 2026

AI Agents Exploit Zero-Days to Breach Hugging Face via Reward Hacking

August 27, 2026

Comments are closed.

Latest Posts

Operation QUICSILVER Strikes Myanmar Government and IT with Backdoor Attack

September 1, 2026

Mirage2FA Surge: 4,500 US & EU Companies Under Attack via Microsoft 365 Logins

August 29, 2026

Active Gitea RCE Exploitation Delivers Miner-Like Payload

August 26, 2026

New Agent Data Injection Attack Traps AI Agents Into Mischief

August 20, 2026
Don't Miss

Urgent: Court Software Breach Risks Exposure of SSNs and Confidential Data

By Staff WriterSeptember 3, 2026

Quick Takeaways An unauthorized breach in Thomson Reuters’ court case management system affects courts across…

Critical flaw exploited to steal nuclear records from Philippine research agency

August 28, 2026

AI Agents Exploit Zero-Days to Breach Hugging Face via Reward Hacking

August 27, 2026

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Recent Posts

  • Exploit Attempts Targeting Super Forms, Elementor Pro RCE Flaws
  • Unisys deploys Microsoft AI for enhanced threat detection
  • Did ShinyHunters Breach ReliaQuest?
  • Urgent: Court Software Breach Risks Exposure of SSNs and Confidential Data
  • AI memory poisoning enables stealthy attack manipulation
About Us
About Us

Welcome to The CISO Brief, your trusted source for the latest news, expert insights, and developments in the cybersecurity world.

In today’s rapidly evolving digital landscape, staying informed about cyber threats, innovations, and industry trends is critical for professionals and organizations alike. At The CISO Brief, we are committed to providing timely, accurate, and insightful content that helps security leaders navigate the complexities of cybersecurity.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Exploit Attempts Targeting Super Forms, Elementor Pro RCE Flaws

September 4, 2026

Unisys deploys Microsoft AI for enhanced threat detection

September 3, 2026

Did ShinyHunters Breach ReliaQuest?

September 3, 2026
Most Popular

CISA Alerts: Critical Vulnerability in Splunk Enterprise Under Active Attack

June 19, 2026152 Views

Salesforce Disables Klue App After Data Breach from Token Abuse

June 19, 2026150 Views

Gefährliche Angriffe: Wie Cyberkriminelle Ihre Identität angreifen

January 29, 2026144 Views

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025

Categories

  • Compliance
  • Cyber Updates
  • Cybercrime and Ransomware
  • Editor's pick
  • Emerging Tech
  • Events
  • Featured
  • Insights
  • Most Read
  • Threat Intelligence
  • Uncategorized
© 2026 thecisobrief. Designed by thecisobrief.
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions

Type above and press Enter to search. Press Esc to cancel.