Nigerian Police Arrest Suspects Behind Raccoon0365 Microsoft 365 Phishing Operation

Listen to this Post

Featured Image

Introduction: A Major Blow to Global Phishing Infrastructure

Cybercrime targeting cloud-based productivity platforms has become one of the most persistent threats to organizations worldwide. Microsoft 365, used daily by millions of businesses, has been a prime target for attackers seeking credentials, access to sensitive data, and direct financial gain. In a significant development, Nigerian law enforcement has arrested multiple suspects linked to a large-scale phishing operation known as Raccoon0365, a platform responsible for thousands of compromised Microsoft 365 accounts across nearly a hundred countries. The arrests highlight the growing role of international cooperation between technology companies and law enforcement agencies in dismantling cybercriminal ecosystems.

Summary of the Original Law Enforcement Strikes at Raccoon0365

The Nigerian Police Force has arrested three individuals connected to targeted Microsoft 365 cyberattacks carried out through the Raccoon0365 phishing platform. These attacks resulted in business email compromise incidents, data breaches, and substantial financial losses for organizations around the world.

The operation was enabled by intelligence shared by Microsoft with the Nigeria Police Force National Cybercrime Centre (NPF–NCCC), with coordination support from the FBI. Investigators identified individuals believed to be responsible for administering Raccoon0365, a phishing toolkit designed to automate the creation of fake Microsoft login pages used to steal credentials.

Raccoon0365 had a massive global reach. Before being disrupted, the service was linked to at least 5,000 compromised Microsoft 365 accounts across 94 countries. Microsoft and Cloudflare disrupted the infrastructure behind the phishing service in September of last year, although it remains unclear whether that takedown directly contributed to identifying the suspects now arrested in Nigeria.

According to the police, operatives were deployed to Lagos and Edo States following precise intelligence. Search operations at the suspects’ residences led to the seizure of laptops, mobile phones, and other digital devices, which forensic analysis later linked to the phishing operation.

One of the arrested individuals is identified as Okitipi Samuel, also known online as “RaccoonO365” and “Moses Felix.” Authorities believe Samuel was the developer of the Raccoon0365 phishing platform. He allegedly ran a Telegram channel where phishing kits were sold to other cybercriminals in exchange for cryptocurrency.

The platform relied heavily on Cloudflare infrastructure, with phishing pages hosted using accounts registered with compromised credentials. At the time of disruption, the Telegram channel reportedly had more than 800 members, with access fees ranging from $355 per month to $999 for three months.

Cloudflare has previously stated that Raccoon0365 was primarily used by Russia-based cybercriminals, underscoring the international nature of the threat. However, Nigerian police noted that they currently have no evidence linking the other two arrested individuals to the creation or administration of the phishing service.

Notably absent from the announcement is Joshua Ogundipe, previously identified by Microsoft as the leader of the phishing operation. Microsoft was contacted for further clarification, but no official comment was immediately available at the time of reporting.

What Undercode Say: Why This Case Matters More Than It Appears

The Raccoon0365 arrests are significant not just because of the individuals involved, but because they expose how modern phishing operations function as scalable, commercialized services. This was not a lone hacker sending random emails; it was a structured platform offering subscription-based phishing tools, customer support via Telegram, and infrastructure that could be rapidly redeployed.

From an operational perspective, Raccoon0365 reflects the maturity of phishing-as-a-service ecosystems. By automating the creation of fake Microsoft 365 login pages, the platform lowered the technical barrier for cybercriminals. Anyone willing to pay could launch targeted campaigns against enterprises, schools, and government agencies without deep technical knowledge.

The use of Cloudflare-hosted infrastructure, combined with accounts created using stolen credentials, shows how attackers exploit trusted internet services to blend in with legitimate traffic. This complicates detection efforts and increases the lifespan of malicious campaigns before takedown.

The collaboration between Microsoft, the FBI, and Nigerian authorities also marks an important shift. Historically, many cybercriminals operated with a sense of immunity, especially when operating across borders. This case demonstrates that intelligence sharing between private companies and national cybercrime units can translate into real-world arrests, even when the victims and infrastructure are globally distributed.

Another critical point is the financial model behind Raccoon0365. Subscription fees nearing $1,000 for a few months of access indicate strong demand and high profitability. This reinforces the idea that phishing is no longer a side activity for criminals; it is a business model with recurring revenue, marketing channels, and brand recognition within underground communities.

The absence of Joshua Ogundipe from the arrest announcement raises questions. It may suggest incomplete attribution, operational compartmentalization within the group, or ongoing investigations. Cybercriminal networks often deliberately separate development, sales, and operations to reduce risk, and this case appears to fit that pattern.

Finally, the global reach of Raccoon0365 highlights a persistent weakness in identity security. Even with widespread awareness of phishing, credential theft remains effective, particularly when attackers leverage trusted brands like Microsoft. This underscores the urgent need for stronger identity protections, including phishing-resistant multi-factor authentication and improved user education.

Fact Checker Results

✅ Nigerian police confirmed the arrest of three individuals linked to Microsoft 365 phishing operations.
✅ Raccoon0365 was previously disrupted by Microsoft and Cloudflare after thousands of account compromises.
❌ The direct role of all arrested suspects in developing or leading the platform has not been fully established.

Prediction: What Comes Next for Phishing-as-a-Service

🔮 More arrests are likely as intelligence gathered from seized devices is analyzed.
🔮 Phishing platforms will continue to evolve, shifting infrastructure and branding to evade takedowns.
🔮 Cloud providers and identity platforms will accelerate adoption of phishing-resistant authentication to reduce the effectiveness of credential theft.

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: www.bleepingcomputer.com
Extra Source Hub (Possible Sources for article):
https://www.quora.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2
Bing

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon