Microsoft and Cloudflare have successfully dismantled a sophisticated phishing operation called RaccoonO365 that compromised thousands of Microsoft 365 accounts worldwide. The joint operation, conducted in September 2025, represents a significant victory against cybercrime-as-a-service platforms.
## The Scale of the Attack
The RaccoonO365 operation, tracked by Microsoft as Storm-2246, operated as a Phishing-as-a-Service (PhaaS) platform that enabled cybercriminals to steal credentials with minimal technical expertise. Since July 2024, the group successfully compromised at least 5,000 Microsoft credentials across 94 countries.
The operation’s reach was extensive, targeting over 2,300 U.S. organizations in a single tax-themed campaign in April 2025. Healthcare organizations were particularly vulnerable, with more than 20 U.S. medical facilities falling victim to these attacks.
## How the Operation Worked
RaccoonO365 operated through a private Telegram channel with over 840 members, offering subscription-based phishing kits with sophisticated features:
– **CAPTCHA pages** and anti-bot techniques to appear legitimate
– **Evasion capabilities** to avoid security analysis
– **Subscription pricing** ranging from $355 for 30 days to $999 for 90 days
– **Cryptocurrency payments** accepted in USDT and Bitcoin
Microsoft estimates the group generated at least $100,000 in revenue, suggesting 100-200 active subscriptions, though the actual number may be significantly higher.
## Real-World Impact
The stolen credentials weren’t just collected—they were weaponized for serious crimes including:
– Financial fraud attempts
– Extortion attacks
– Initial access for ransomware deployment
– Compromise of OneDrive, SharePoint, and email accounts
“This puts public safety at risk, as RaccoonO365 phishing emails are often a precursor to malware and ransomware,” explained Steven Masada from Microsoft’s Digital Crimes Unit. Healthcare attacks were particularly concerning, causing delayed patient services, postponed critical care, and compromised lab results.
## The Takedown
The coordinated effort between Microsoft’s Digital Crimes Unit and Cloudflare’s security teams resulted in:
– **338 websites and Worker accounts seized**
– **Identification of the operation’s leader**: Joshua Ogundipe from Nigeria
– **Criminal referral** sent to international law enforcement
– **Operational security breach** that exposed the group’s cryptocurrency wallet
Investigators discovered that Ogundipe, who has a computer programming background, authored most of the malicious code. The operation also showed connections to Russian-speaking cybercriminals.
## Broader Context
This takedown follows Microsoft’s previous success in May 2025, when they seized 2,300 domains linked to the Lumma malware-as-a-service operation. These coordinated efforts demonstrate the growing effectiveness of public-private partnerships in combating sophisticated cybercrime operations.
The RaccoonO365 disruption highlights the evolving threat landscape where cybercrime-as-a-service platforms lower the barrier to entry for malicious actors, making coordinated international responses increasingly critical for cybersecurity.
