What happened
Microsoft's Digital Crimes Unit, with Cloudflare and Health-ISAC, obtained a court order and seized 338 websites underpinning RaccoonO365, a subscription phishing kit that impersonated Microsoft sign-in pages. Microsoft said the service had stolen at least 5,000 Microsoft 365 credentials across 94 countries since July 2024, including in campaigns against more than twenty US healthcare organisations, and it named the Nigeria-based operator behind it.
How the deception worked
Subscribers paid a monthly fee for ready-made kits that produced convincing Microsoft 365 sign-in pages and matching lure emails, often disguised as document-sharing or tax notices. Victims clicked through and entered credentials into a page that looked exactly like their employer's login, and the kit relayed the session in real time so that multi-factor prompts were captured and session cookies stolen, defeating MFA. Built-in CAPTCHA gates and detection evasion kept security scanners away from the landing pages. The kit lowered the skill floor so far that non-technical criminals could run credible corporate phishing, and an AI add-on was marketed to scale the campaigns further.
AI involvement · Confirmed AI-enabled
The service advertised an AI-assisted add-on to help subscribers build and scale phishing campaigns.
The control that would have caught it· our reading, not a claim from the sources
Phishing-resistant authentication such as passkeys or FIDO2 removes the value of relayed session cookies, which is what these adversary-in-the-middle kits are built to steal.
Sources (2)
- Microsoft seizes 338 websites to disrupt rapidly growing 'RaccoonO365' phishing serviceMicrosoft On the Issues·blogs.microsoft.comOpen ↗
- Microsoft and Cloudflare disrupt massive RaccoonO365 phishing serviceBleepingComputer·bleepingcomputer.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.