Microsoft and Cloudflare Crush Global Phishing Empire: 338 Domains Seized After Criminals Steal 5,000+ Credentials Across 94 Countries

# Microsoft and Cloudflare Dismantle Major Phishing Operation Targeting Microsoft 365 Users

Microsoft’s Digital Crimes Unit (DCU) has successfully dismantled a sophisticated phishing operation that compromised over 5,000 Microsoft 365 accounts across 94 countries. Working alongside Cloudflare, the tech giant seized 338 malicious domains operated by RaccoonO365, a cybercriminal group offering phishing-as-a-service (PhaaS) tools.

## The RaccoonO365 Threat

RaccoonO365, tracked by Microsoft as Storm-2246, operated as a subscription-based service that made cybercrime accessible to virtually anyone. The group offered:

– **30-day plans** for $355
– **90-day plans** for $999
– Capability to target up to 9,000 email addresses daily
– Advanced techniques to bypass multi-factor authentication

The service has been active since September 2024, generating over $100,000 in cryptocurrency payments through an estimated 100-200 subscriptions sold via an 850-member Telegram channel.

## How the Attacks Worked

The phishing campaigns impersonated trusted brands including Microsoft, DocuSign, SharePoint, Adobe, and Maersk. Victims received fraudulent emails directing them to convincing lookalike pages designed to steal their Microsoft 365 credentials.

What made these attacks particularly dangerous was their use of legitimate security tools:
– **Cloudflare Turnstile** as CAPTCHA verification
– **Bot detection scripts** to ensure only intended targets could access phishing pages
– **AI-powered services** for scaling operations and increasing attack sophistication

## The Takedown Operation

Using a court order from the Southern District of New York, the coordinated takedown occurred between September 2-8, 2025, involving:

– Seizure of 338 malicious domains
– Placement of warning pages on compromised sites
– Termination of associated scripts and user accounts
– Complete disruption of the group’s technical infrastructure

## Impact and Attribution

The operation targeted over 2,300 U.S. organizations, including at least 20 healthcare entities. Microsoft identified Joshua Ogundipe, a Nigeria-based individual, as the mastermind behind RaccoonO365. The attribution was possible due to an operational security mistake that exposed a secret cryptocurrency wallet.

While Ogundipe and four co-conspirators remain at large, Microsoft has referred the case to international law enforcement.

## Industry Response

Following the disruption, the threat actors announced they were “scrapping all legacy RaccoonO365 links” and offered affected customers compensation with extended subscriptions. Cloudflare emphasized that this represents a shift from reactive, single-domain takedowns to proactive, large-scale disruptions.

This case demonstrates how simple tools can enable widespread cybercrime, putting millions of users at risk while generating substantial profits for criminal organizations. The successful collaboration between Microsoft and Cloudflare sets a precedent for future coordinated efforts against cybercriminal infrastructure.

Share This Article