Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Resolve AI, a startup led by former Splunk executives, reaches $1 billion Series A valuation

Establish a venture-backable company in a highly regulated field

Cursor continues acquisition spree with deal with Graphite

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Nigeria arrests RaccoonO365 phishing developer involved in Microsoft 365 attack
Identity

Nigeria arrests RaccoonO365 phishing developer involved in Microsoft 365 attack

userBy userDecember 19, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

December 19, 2025Ravi LakshmananCybercrime/Law Enforcement

Nigerian authorities announced the arrest of three “prominent internet fraud suspects” suspected of involvement in phishing attacks targeting major companies, including the main developer of the RaccoonO365 phishing-as-a-service (PhaaS) scheme.

The Nigeria Police National Cyber ​​Crime Center (NPF-NCCC) said an investigation conducted in collaboration with Microsoft and the Federal Bureau of Investigation (FBI) identified Okitipi Samuel, also known as Moses Felix, as the main suspect and developer of the phishing infrastructure.

“The investigation revealed that he operated a Telegram channel selling phishing links in exchange for cryptocurrency and hosted a fraudulent login portal on Cloudflare using stolen or fraudulently obtained email credentials,” NPF said in a post shared on social media.

Additionally, search operations conducted at their residences resulted in the seizure of laptops, mobile devices, and other digital equipment related to the operation. According to the NPF, the other two arrested individuals had no connection to the creation or operation of the PhaaS service.

cyber security

RaccoonO365 is the name assigned to the financially motivated threat group behind PhaaS toolkits. The PhaaS toolkit allows malicious attackers to conduct credential harvesting attacks by providing a phishing page that mimics the Microsoft 365 login page. Microsoft is tracking this attacker under the name Storm-2246.

Back in September 2025, the tech giant announced that it had worked with Cloudflare to seize 338 domains used by RaccoonO365. Phishing infrastructure attributed to this toolkit is estimated to have stolen at least 5,000 Microsoft credentials from 94 countries since July 2024.

NPF said RaccoonO365 was used to set up fraudulent Microsoft login portals to steal user credentials and gain unauthorized access to email platforms of businesses, financial institutions, and educational institutions. A joint investigation revealed multiple incidents of unauthorized access to Microsoft 365 accounts from January to September 2025 resulting from phishing messages crafted to mimic legitimate Microsoft authentication pages.

These activities resulted in business email compromises, data breaches, and financial losses across multiple jurisdictions, NPF added.

A civil lawsuit filed in September by Microsoft and Health-ISAC accuses defendant Joshua Ogundipe and four other John Does of hosting a cybercrime operation by “selling, distributing, purchasing, and implementing” phishing kits that facilitate sophisticated spear phishing and the exfiltration of sensitive information.

The stolen data is used to facilitate further cybercrime such as business email compromise, financial fraud, ransomware attacks, and even intellectual property infringement.

cyber security

The development comes after Google filed a lawsuit against the operators of the Darcula PhaaS service and named Chinese national Yucheng Chang as the group’s leader, along with 24 other members. The company is seeking a court order to seize the group’s server infrastructure, which is behind a massive smishing wave masquerading as a U.S. government agency.

News of the lawsuit was first reported by NBC News on December 17, 2025. The development comes more than a month after Google sued China-based hackers associated with another PhaaS service known as Lighthouse, which allegedly affected more than 1 million users in 120 countries.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleEuropa Clipper reveals unique observations of interstellar comets
Next Article 2025 Urids meteor shower: When and where to see ‘shooting stars’ on the longest night of the year
user
  • Website

Related Posts

Russian-linked hackers use Microsoft 365 device code phishing to take over accounts

December 19, 2025

Cracked software and YouTube videos spread CountLoader and GachiLoader malware

December 19, 2025

WatchGuard warns of active exploitation of critical Fireware OS VPN vulnerability

December 19, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Resolve AI, a startup led by former Splunk executives, reaches $1 billion Series A valuation

Establish a venture-backable company in a highly regulated field

Cursor continues acquisition spree with deal with Graphite

Elon Musk’s $56 billion Tesla pay package reinstated by Delaware Supreme Court

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.