Technology NewsTechnology NewsTechnology News
  • Computing
  • AI
  • Robotics
  • Cybersecurity
  • Electric Vehicle
  • Wearables
  • Gaming
  • Space
Reading: Microsoft Seizes Hundreds of Phishing Domains in Global Takedown
Share
Font ResizerAa
Technology NewsTechnology News
Font ResizerAa
Search
  • Computing
  • AI
  • Robotics
  • Cybersecurity
  • Electric Vehicle
  • Wearables
  • Gaming
  • Space
Follow US
  • Cookie Policy (EU)
  • Contact
  • About
© 2025 NEWSLINKER - Powered by LK SOFTWARE
Cybersecurity

Microsoft Seizes Hundreds of Phishing Domains in Global Takedown

Highlights

  • Microsoft seized 338 domains linked to RaccoonO365 phishing operations.

  • The toolkit facilitated large-scale credential theft across 94 countries.

  • International legal challenges hamper unified response to cybercrime.

Ethan Moreno
Last updated: 17 September, 2025 - 1:19 am 1:19 am
Ethan Moreno 2 hours ago
Share
SHARE

Microsoft has intensified its efforts against cybercrime, targeting a widespread phishing operation responsible for thousands of credential thefts. Over several months, Microsoft’s Digital Crimes Unit coordinated with partners to dismantle RaccoonO365, a criminal service that enabled the theft of credentials from organizations worldwide. The investigation not only exposed the financial transactions behind the operation but also identified the main operator, marking a significant step in disrupting a rapidly growing cybercriminal market. Despite this takedown, the persistent nature of such attacks highlights the ongoing security challenge facing technology providers and organizations in every sector.

Contents
How did Microsoft Disrupt the RaccoonO365 Operation?What Role Did the RaccoonO365 Toolkit Play?How Is Law Enforcement Addressing International Cybercrime Coordination?

In earlier public reports, phishing-as-a-service kits have gradually become more sophisticated and accessible, but prior campaigns seldom reached the scale demonstrated by RaccoonO365. Distributed phishing kits using Microsoft 365 branding have previously been seen in smaller, isolated incidents. The recent takedown reveals a shift toward industrial-scale operations targeting a wide array of sectors, suggesting that future cybercrime campaigns may be even more difficult to contain. Technical analyses of RaccoonO365 also indicate a higher level of sophistication in bypassing security controls compared to earlier kits.

How did Microsoft Disrupt the RaccoonO365 Operation?

Acting on a court order from the U.S. District Court for the Southern District of New York, Microsoft teamed up with Cloudflare to seize 338 domains linked to the RaccoonO365 phishing service. Chainalysis assisted the effort by tracing cryptocurrency transactions linked to the group’s activities, which led to uncovering the identity of the alleged operator, Joshua Ogundipe. The seized domains were used extensively in campaigns targeting both domestic and international organizations, with a significant concentration on US-based victims.

What Role Did the RaccoonO365 Toolkit Play?

The RaccoonO365 toolkit has seen rapid adoption among cybercriminals, with over 850 members reportedly purchasing access to its phishing kits. Capable of sending vast volumes of phishing emails each day, these kits mimicked Microsoft’s branding to deceive users into surrendering their Microsoft 365 credentials. They incorporated malware evasion techniques, user-agent filtering, and dynamic traffic routing, often bypassing multifactor authentication protections.

How Is Law Enforcement Addressing International Cybercrime Coordination?

While Microsoft located and referred the alleged operator to law enforcement, the company remains cautious about the limitations posed by fragmented international laws. The case underscores the challenge of cross-border investigations and prosecutions, as cybercriminals often take advantage of inconsistent legal frameworks.

“Today’s patchwork of international laws remains a major obstacle and cybercriminals exploit these gaps,”

Steven Masada, assistant general counsel at Microsoft’s DCU, noted, emphasizing the need for greater global collaboration.

RaccoonO365’s phishing campaigns were not limited to one sector; they affected businesses, health care organizations, and public institutions alike. Despite the breadth of the attack, not every compromised credential resulted in further harm, as attackers often use these credentials as entry points for subsequent malware and ransomware schemes. Microsoft’s DCU also operated undercover during the investigation, as principal investigator Maurice Mason shared:

“During the investigation, the DCU engaged directly with the threat actor without disclosing our identity to acquire the phishing kits.”

The international takedown of RaccoonO365 demonstrates the complexities of combating cybercrime in a globally interconnected environment. Cloud-based phishing kits, such as those targeted in this operation, benefit from the ease of online anonymity and cryptocurrency payments. Organizations need to continually improve their detection and response capabilities, while governments must address the legal and technical challenges to effective enforcement. For those managing digital infrastructure, this case highlights the importance of routine security training and robust incident response, since phishing kits will likely continue to evolve—regardless of takedowns.

You can follow us on Youtube, Telegram, Facebook, Linkedin, Twitter ( X ), Mastodon and Bluesky

You Might Also Like

BreachForums Founder Receives Three-Year Prison Sentence After Resentencing

Senators Debate FBI Cyber Staff Cuts as Director Defends Record

Apple Updates Major Devices with Security Patches as iOS 26 Launches

Check Point Expands AI Security Capabilities With Lakera Acquisition

OpenAI and Anthropic Partner with US, UK Agencies to Safeguard AI Models

Share This Article
Facebook Twitter Copy Link Print
Ethan Moreno
By Ethan Moreno
Ethan Moreno, a 35-year-old California resident, is a media graduate. Recognized for his extensive media knowledge and sharp editing skills, Ethan is a passionate professional dedicated to improving the accuracy and quality of news. Specializing in digital media, Moreno keeps abreast of technology, science and new media trends to shape content strategies.
Previous Article BreachForums Founder Receives Three-Year Prison Sentence After Resentencing
Next Article Storage Prices Surge as SSDs and HDDs See Soaring Demand

Stay Connected

6.2kLike
8kFollow
2.3kSubscribe
1.7kFollow

Latest News

Storage Prices Surge as SSDs and HDDs See Soaring Demand
Computing
Rethink Robotics Closes Operations After Second Attempt at Comeback
Robotics
Tesla Semi Joins Uber Program to Accelerate Electric Truck Adoption
Electric Vehicle
Tesla Issues Powerwall 2 Recall in Australia After Fire Reports
Electric Vehicle
Apple Watch Ultra 3 Delivers Upgraded Screen and Connectivity Features
Wearables
NEWSLINKER – your premier source for the latest updates in ai, robotics, electric vehicle, gaming, and technology. We are dedicated to bringing you the most accurate, timely, and engaging content from across these dynamic industries. Join us on our journey of discovery and stay informed in this ever-evolving digital age.

ARTIFICAL INTELLIGENCE

  • Can Artificial Intelligence Achieve Consciousness?
  • What is Artificial Intelligence (AI)?
  • How does Artificial Intelligence Work?
  • Will AI Take Over the World?
  • What Is OpenAI?
  • What is Artifical General Intelligence?

ELECTRIC VEHICLE

  • What is Electric Vehicle in Simple Words?
  • How do Electric Cars Work?
  • What is the Advantage and Disadvantage of Electric Cars?
  • Is Electric Car the Future?

RESEARCH

  • Robotics Market Research & Report
  • Everything you need to know about IoT
  • What Is Wearable Technology?
  • What is FANUC Robotics?
  • What is Anthropic AI?
Technology NewsTechnology News
Follow US
About Us   -  Cookie Policy   -   Contact

© 2025 NEWSLINKER. Powered by LK SOFTWARE
Welcome Back!

Sign in to your account

Register Lost your password?