Microsoft’s Digital Crimes Unit announced that it had partnered with Cloudflare to orchestrate the acquisition of 338 domains utilized by RaccoonO365, a profit-driven threat organization that was responsible for a phishing-as-a-service (Phaas) toolkit that has been used to steal over 5,000 Microsoft 365 login credentials from 94 countries since July 2024.
“The DCU disrupted the operation’s technical infrastructure and cut off criminals’ access to victims by seizing 338 websites linked to the popular service through a court order granted by the Southern District of New York,” stated assistant general counsel Steven Masada of DCU.
Because cybercrime is accessible to almost anybody thanks to easy tools like RaccoonO365, millions of people are at risk. This instance demonstrates that hackers don’t need to be highly skilled to wreak extensive harm.
On September 2, 2025, the first stage of the Cloudflare takedown began, and on September 3 and 4, more steps were taken. This involved suspending the user accounts read more about RaccoonO365 Phishing Network Dismantled as Microsoft Cloudflare Take Down 338 Domains.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
