{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-microsoft-and-cloudflare-seize-338-sites-used-by-raccoono365-phishing-se"},"incident":{"slug":"2025-microsoft-and-cloudflare-seize-338-sites-used-by-raccoono365-phishing-se","title":"Microsoft and Cloudflare seize 338 sites used by RaccoonO365 phishing service","date":"2025-09-16","date_precision":"day","year":2025,"victim_org":"Microsoft 365 customers in 94 countries, including US healthcare organisations","sector":"Technology","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"The service advertised an AI-assisted add-on to help subscribers build and scale phishing campaigns.","outcomes":["Credential Theft","Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":5000,"threat_actor":"Storm-2246 / RaccoonO365 (Nigeria-based operator named by Microsoft)","summary":"Microsoft's Digital Crimes Unit, with Cloudflare and Health-ISAC, obtained a court order and seized 338 websites underpinning RaccoonO365, a subscription phishing kit that impersonated Microsoft sign-in pages. Microsoft said the service had stolen at least 5,000 Microsoft 365 credentials across 94 countries since July 2024, including in campaigns against more than twenty US healthcare organisations, and it named the Nigeria-based operator behind it.","how_it_worked":"Subscribers paid a monthly fee for ready-made kits that produced convincing Microsoft 365 sign-in pages and matching lure emails, often disguised as document-sharing or tax notices. Victims clicked through and entered credentials into a page that looked exactly like their employer's login, and the kit relayed the session in real time so that multi-factor prompts were captured and session cookies stolen, defeating MFA. Built-in CAPTCHA gates and detection evasion kept security scanners away from the landing pages. The kit lowered the skill floor so far that non-technical criminals could run credible corporate phishing, and an AI add-on was marketed to scale the campaigns further.","lessons":"Phishing-resistant authentication such as passkeys or FIDO2 removes the value of relayed session cookies, which is what these adversary-in-the-middle kits are built to steal.","confidence":"Confirmed","sources":[{"title":"Microsoft seizes 338 websites to disrupt rapidly growing 'RaccoonO365' phishing service","url":"https://blogs.microsoft.com/on-the-issues/2025/09/16/microsoft-seizes-338-websites-to-disrupt-rapidly-growing-raccoono365-phishing-service/","publisher":"Microsoft On the Issues"},{"title":"Microsoft and Cloudflare disrupt massive RaccoonO365 phishing service","url":"https://www.bleepingcomputer.com/news/security/microsoft-and-cloudflare-disrupt-massive-raccoono365-phishing-service/","publisher":"BleepingComputer"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-microsoft-and-cloudflare-seize-338-sites-used-by-raccoono365-phishing-se"}}