financetom
Business
financetom
/
Business
/
Microsoft seizes 340 websites linked to growing phishing subscription service
News World Market Environment Technology Personal Finance Politics Retail Business Economy Cryptocurrency Forex Stocks Market Commodities
Microsoft seizes 340 websites linked to growing phishing subscription service
Sep 16, 2025 11:36 AM

*

Microsoft ( MSFT ) obtained court order to seize domains

*

Raccoon0365 targeted over 2,300 organizations with

tax-themed

phishing campaigns in February

*

Operators generated $100,000 in cryptocurrency since July

2024,

Microsoft ( MSFT ) says

By AJ Vicens

Sept 16 (Reuters) - Microsoft Inc said on Tuesday that

it seized nearly 340 websites tied to a rapidly growing

Nigerian-based service that allowed users to carry out phishing

operations that stole at least 5,000 Microsoft ( MSFT ) user credentials.

Microsoft ( MSFT ) obtained an order from the U.S. District

Court in Manhattan earlier this month to seize domains

associated with Raccoon0365, the subscription service that

allowed users to carry out massive phishing campaigns, which

sometimes involved thousands of emails at a time, according to

Steven Masada, assistant general counsel for Microsoft's ( MSFT ) Digital

Crimes Unit.

Raccoon0365's service, which operates through a private

Telegram channel with more than 850 subscribers, enables users

to impersonate trusted brands and get targets to enter Microsoft ( MSFT )

login credentials on phony Microsoft ( MSFT ) login pages, Masada said in

a blog posted on Microsoft's ( MSFT ) website.

The service has generated for its small group of operators at

least $100,000 in cryptocurrency payments since launching in

July 2024, Masada said in the blog.

Microsoft ( MSFT ) said the seizure of the websites occurred over a

period of days earlier this month.

Microsoft ( MSFT ) identified Nigeria-based Joshua Ogundipe as the leader

and main operator of Raccoon0365. Ogundipe did not immediately

respond to an email request for comment sent to the email

address identified by Microsoft ( MSFT ) in its court filing.

"Cybercriminals don't need to be sophisticated to cause

widespread harm," Masada said. "Simple tools like Raccoon0365

make cybercrime accessible to virtually anyone, putting millions

of users at risk."

Raccoon0365 subscribers have targeted a wide swath of

industries, Masada said, and separate court filings allege that

"a significant portion" of Raccoon0365 activity targets

organizations based in New York City.

Masada said Microsoft ( MSFT ) identified what it said was a

Raccoon0365-related effort using tax-themed phishing emails to

target more than 2,300 organizations, mostly in the U.S.,

between February 12 and February 28 this year, according to a

company blog posted in April.

Errol Weiss, chief security officer of the Health Information

Sharing & Analysis Center (Health-ISAC), which provides

cybersecurity services to member health organizations and is a

co-plaintiff alongside Microsoft ( MSFT ), said Raccoon0365 has been

linked to successful credential harvesting through phishing

campaigns at at least five unnamed healthcare organizations,

while targeting 25 health sector organizations overall.

Once hackers gain that access, any number of things can happen,

Weiss said.

"So many of the attacks start because somebody gave up their

user name and password to a bad guy," Weiss said in an

interview. "Once that cybercriminal has access to the network,

then it's just up to the imagination in terms of what comes next

and how they monetize it."

The Raccoon0365 operators used services provided by Cloudflare

to help hide the service's backend infrastructure, the internet

services firm said in its own blog post. Cloudflare worked with

Microsoft ( MSFT ) and the U.S. Secret Service to disrupt Raccoon0365

operations on its platform and prevent the operators from

establishing new accounts, the company said.

Blake Darché, the head of threat intelligence at Cloudflare,

said in an interview that the Raccoon0365 operators made some

key operational security mistakes but were highly effective.

"They're in people's accounts, they compromise lots of people,

and it needs to obviously be stopped," he said.

Comments
Welcome to financetom comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
Related Articles >
Sector Update: Consumer Stocks Edge Higher Pre-Bell Tuesday
Sector Update: Consumer Stocks Edge Higher Pre-Bell Tuesday
May 27, 2025
09:17 AM EDT, 05/27/2025 (MT Newswires) -- Consumer stocks were edging higher pre-bell Tuesday, with The Consumer Discretionary Select Sector SPDR Fund ( XLY ) up 1.5% and The Consumer Staples Select Sector SPDR Fund ( XLP ) 0.3% higher. PDD Holdings ( PDD ) shares were down more than 17% after the company reported Q1 non-GAAP earnings and revenue...
Trump Media to raise $2.5 billion to fund bitcoin treasury
Trump Media to raise $2.5 billion to fund bitcoin treasury
May 27, 2025
May 27 (Reuters) - Trump Media and Technology Group ( DJT ) has entered into agreements with institutional investors to raise about $2.5 billion for the creation of a bitcoin treasury, U.S. President Donald Trump's social media firm said on Tuesday. ...
IMAX Delivers $31 Million in Ticket Sales From Latest 'Mission: Impossible' Film
IMAX Delivers $31 Million in Ticket Sales From Latest 'Mission: Impossible' Film
May 27, 2025
09:15 AM EDT, 05/27/2025 (MT Newswires) -- IMAX ( IMAX ) said Tuesday the latest installment of the Mission: Impossible film franchise delivered $31 million in ticket sales in the IMAX ( IMAX ) global network through Monday, which is 14.2% of the film's global box office. Mission: Impossible - The Final Reckoning posed the biggest IMAX ( IMAX )...
Google agrees $36 million fine for anti-competitive deals with Australia telcos
Google agrees $36 million fine for anti-competitive deals with Australia telcos
Aug 17, 2025
SYDNEY, Aug 18 (Reuters) - Google agreed on Monday to pay a A$55 million ($35.8 million) fine in Australia after the consumer watchdog found it had hurt competition by paying the country's two largest telcos to pre-install its search application on Android phones, excluding rival search engines. The fine extends a bumpy period for the Alphabet-owned internet giant in Australia,...
Copyright 2023-2026 - www.financetom.com All Rights Reserved