financetom
Business
financetom
/
Business
/
Microsoft seizes 340 websites linked to growing phishing subscription service
News World Market Environment Technology Personal Finance Politics Retail Business Economy Cryptocurrency Forex Stocks Market Commodities
Microsoft seizes 340 websites linked to growing phishing subscription service
Sep 16, 2025 11:36 AM

*

Microsoft ( MSFT ) obtained court order to seize domains

*

Raccoon0365 targeted over 2,300 organizations with

tax-themed

phishing campaigns in February

*

Operators generated $100,000 in cryptocurrency since July

2024,

Microsoft ( MSFT ) says

By AJ Vicens

Sept 16 (Reuters) - Microsoft Inc said on Tuesday that

it seized nearly 340 websites tied to a rapidly growing

Nigerian-based service that allowed users to carry out phishing

operations that stole at least 5,000 Microsoft ( MSFT ) user credentials.

Microsoft ( MSFT ) obtained an order from the U.S. District

Court in Manhattan earlier this month to seize domains

associated with Raccoon0365, the subscription service that

allowed users to carry out massive phishing campaigns, which

sometimes involved thousands of emails at a time, according to

Steven Masada, assistant general counsel for Microsoft's ( MSFT ) Digital

Crimes Unit.

Raccoon0365's service, which operates through a private

Telegram channel with more than 850 subscribers, enables users

to impersonate trusted brands and get targets to enter Microsoft ( MSFT )

login credentials on phony Microsoft ( MSFT ) login pages, Masada said in

a blog posted on Microsoft's ( MSFT ) website.

The service has generated for its small group of operators at

least $100,000 in cryptocurrency payments since launching in

July 2024, Masada said in the blog.

Microsoft ( MSFT ) said the seizure of the websites occurred over a

period of days earlier this month.

Microsoft ( MSFT ) identified Nigeria-based Joshua Ogundipe as the leader

and main operator of Raccoon0365. Ogundipe did not immediately

respond to an email request for comment sent to the email

address identified by Microsoft ( MSFT ) in its court filing.

"Cybercriminals don't need to be sophisticated to cause

widespread harm," Masada said. "Simple tools like Raccoon0365

make cybercrime accessible to virtually anyone, putting millions

of users at risk."

Raccoon0365 subscribers have targeted a wide swath of

industries, Masada said, and separate court filings allege that

"a significant portion" of Raccoon0365 activity targets

organizations based in New York City.

Masada said Microsoft ( MSFT ) identified what it said was a

Raccoon0365-related effort using tax-themed phishing emails to

target more than 2,300 organizations, mostly in the U.S.,

between February 12 and February 28 this year, according to a

company blog posted in April.

Errol Weiss, chief security officer of the Health Information

Sharing & Analysis Center (Health-ISAC), which provides

cybersecurity services to member health organizations and is a

co-plaintiff alongside Microsoft ( MSFT ), said Raccoon0365 has been

linked to successful credential harvesting through phishing

campaigns at at least five unnamed healthcare organizations,

while targeting 25 health sector organizations overall.

Once hackers gain that access, any number of things can happen,

Weiss said.

"So many of the attacks start because somebody gave up their

user name and password to a bad guy," Weiss said in an

interview. "Once that cybercriminal has access to the network,

then it's just up to the imagination in terms of what comes next

and how they monetize it."

The Raccoon0365 operators used services provided by Cloudflare

to help hide the service's backend infrastructure, the internet

services firm said in its own blog post. Cloudflare worked with

Microsoft ( MSFT ) and the U.S. Secret Service to disrupt Raccoon0365

operations on its platform and prevent the operators from

establishing new accounts, the company said.

Blake Darché, the head of threat intelligence at Cloudflare,

said in an interview that the Raccoon0365 operators made some

key operational security mistakes but were highly effective.

"They're in people's accounts, they compromise lots of people,

and it needs to obviously be stopped," he said.

Comments
Welcome to financetom comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
Related Articles >
SoftBank's PayPay prices IPO at $16 per share, filing shows
SoftBank's PayPay prices IPO at $16 per share, filing shows
Mar 11, 2026
TOKYO, March 12 (Reuters) - Japanese digital wallet provider PayPay, backed by SoftBank Group, has priced its initial public offering at $16 per share, a filing from SoftBank subsidiary LY Corp showed. PayPay initially wanted to sell shares in a range between $17 to $20 per share but sources told Reuters that it was likely to be around the low...
UK watchdogs press Meta, TikTok, Snap and YouTube to block children
UK watchdogs press Meta, TikTok, Snap and YouTube to block children
Mar 11, 2026
LONDON, March 12 (Reuters) - Britain's media and privacy regulators on Thursday demanded that major social media platforms do more to keep children off their services, warning that companies were failing to enforce their own minimum age rules. Britain has been weighing tougher curbs on children's access to social media, with the government considering barring under 16s from such platforms...
BRIEF-Ly Corp - Paypay Announces Pricing Of Initial Public Offering
BRIEF-Ly Corp - Paypay Announces Pricing Of Initial Public Offering
Mar 11, 2026
March 12 (Reuters) - LY Corp ( YAHOF ): * LY CORP ( YAHOF ) - PAYPAY ANNOUNCES PRICING OF INITIAL PUBLIC OFFERING * LY CORP ( YAHOF ) - PAYPAY SET PRICE OF INITIAL PUBLIC OFFERING AT $16 PER ADS Source text: Further company coverage: ...
Factbox-How have US presidents tapped strategic petroleum reserves during war?
Factbox-How have US presidents tapped strategic petroleum reserves during war?
Mar 11, 2026
WASHINGTON, March 11 (Reuters) - The U.S. plans to release 172 million barrels of oil from its Strategic Petroleum Reserve, more than 40% of a wider release coordinated with allies, to help dampen prices spiked by supply disruptions from the U.S.-Israeli war on Iran. The U.S. sale, announced late on Wednesday, is part of a 400-million-barrel release by members of...
Copyright 2023-2026 - www.financetom.com All Rights Reserved