Microsoft Disrupts Major Phishing Operation Targeting Microsoft 365

Microsoft dismantled a major phishing service stealing Microsoft 365 credentials.

Sep 18, 2025
2 minute read
eSecurity Planet のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

Microsoft’s Digital Crimes Unit recently announced the successful dismantling of a large-scale phishing operation aimed at stealing Microsoft 365 credentials. 

The investigation culminated in the seizure of hundreds of domains supporting the RaccoonO365 service, which enabled widespread credential theft against organizations worldwide.

Industrializing phishing-as-a-service

The RaccoonO365 platform, internally tracked as Storm-2246, illustrates the growing “cybercrime-as-a-service” trend. 

The service allowed its customers to deploy sophisticated credential theft campaigns with minimal technical expertise. Investigators found that the operators relied on automation to streamline phishing workflows, making large-scale attacks accessible to less-skilled actors.

The group behind RaccoonO365 reportedly developed new tools to improve the effectiveness of phishing lures, including the use of artificial intelligence to craft more convincing messages. 

Researchers noted that the service was promoted through private online channels, further expanding its reach within underground communities.

Operational security lapse

Microsoft traced the phishing network to an individual in Nigeria, identifying the suspect after an operational security lapse exposed a cryptocurrency wallet tied to the scheme. 

This discovery connected the organizer to financial transactions supporting the enterprise. Several co-conspirators remain under investigation, and Microsoft has referred the case to law enforcement agencies.

Campaigns attributed to the group targeted organizations across multiple sectors, including healthcare, finance, and government. Attackers leveraged tax-themed lures and other social engineering tactics to deliver credential-stealing malware, bypassing some traditional security defenses.

Advertisement

Implications for cybersecurity

The takedown of RaccoonO365 underscores the evolving nature of phishing threats. Although this disruption removed a significant amount of malicious infrastructure, the underlying model—offering phishing capabilities as a commercial service—continues to proliferate. Other groups have adopted similar techniques, registering new domains and refining methods to avoid detection.

Researchers have also observed attackers using legitimate cloud services to mask malicious activity, complicating efforts to block phishing at the network level. This highlights the need for layered defenses that extend beyond simple email filtering.

Strengthening defenses

Organizations and individuals can mitigate risks from phishing-as-a-service operations by adopting strong authentication practices. 

Enabling multi-factor authentication (MFA) remains one of the most effective safeguards against credential compromise, even when phishing emails succeed in reaching users.

Security teams should also monitor domain registrations, enhance endpoint protections, and educate employees about emerging lures. Proactive measures, combined with industry collaboration and law enforcement actions, can significantly disrupt criminal ecosystems.

Microsoft’s action against RaccoonO365 demonstrates how coordinated efforts between technology providers, investigators, and the courts can meaningfully reduce large-scale phishing activity. 

Yet the incident also serves as a reminder that crime-as-a-service models are adaptable and persistent. Continued vigilance, robust authentication, and user awareness are essential for defending against these evolving threats.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。