Nigeria har påstået raccoono365 udvikler, mens microsoft nye york jakkesæt navne en anden leder

Microsoft "s Digital Crimes Unit brugt september 2025 beslaglæggelse domæner. Nigerias National Cybercrime Centre brugte december 2025 booking en mand, hvis navn ikke var på Microsofts civile klage. Disse to tidslinjer ikke linje op, og at mismatch er nu den levende del af RaccoonO365 fil.
Officers in Lagos and Edo States detained Okitipi Samuel, also known as Moses Felix and RaccoonO365, as the alleged developer of a phishing-as-a-service kit that sold counterfeit Microsoft 365 login pages for cryptocurrency. Two other people taken in the same sweeps were later released. Police said they found no evidence those two built or ran the platform. The man Microsoft had already sued in New York as the ringleader, Joshua Ogundipe of Benin City, was not named in the Nigerian police statement that followed the raids. Microsoft had referred him for international prosecution. His public whereabouts stayed unclear.
Denne opdeling er ikke en fodnote. Det er grunden til et domæne beslaglæggelse på Manhattan og en booking ark i Lagos kan både være sandt og stadig forlade butikken påståede arkitekt off kamera.
Et abonnement skrivebord, ikke en enlig kælder hacker
RaccoonO365 was merchandised like software-as-a-service. Operators charged about $355 for 30 days and $999 for 90 days, payable only in crypto. Buyers received generated pages that copied Microsoft, DocuSign, SharePoint, Adobe, and Maersk sign-in screens. Finance, human resources, and invoice themes filled the rest of the lure. Telegram channels tied to the shop counted more than 850 members. Recorded crypto payments topped $100,000. Senders could hit as many as 9,000 targets in a day.
Researchers say the service ran from at least July 2024 and harvested more than 5,000 Microsoft 365 credentials across 94 countries. The technical trick was an adversary-in-the-middle proxy. The fake page talked to Microsoft’s real servers, so the kit could lift passwords, multi-factor codes, and live session cookies in one pass. Cloudflare Turnstile CAPTCHA screens made the pages look like ordinary corporate gates. Cloudflare later said the customer base was mainly Russia-based crews. By late 2025 the operators were pitching an add-on called RaccoonO365 AI-MailCheck, a filter meant to score which stolen mailboxes were worth keeping.
Microsoft tracks the crew as Storm-2246. In April 2026, Digital Crimes Unit investigators described the September disruption under the internal name Operation Trashpanda, walking through how branding, Telegram sales, and AI-assisted targeting lowered the cost of entry for people who could not write an exploit themselves. Details of the Nigerian probe were first laid out by Record og BleepingComputer.
Tre hundrede tredivte-otte domæner kom ned først
The police work followed a civil and technical takedown. Microsoft’s Digital Crimes Unit, Cloudflare’s Cloudforce One team, and Chainalysis used an order from the U.S. District Court for the Southern District of New York to seize 338 domains in September 2025. Microsoft and Health-ISAC sued Ogundipe and four John Does under the Computer Fraud and Abuse Act, RICO, and the Electronic Communications Privacy Act. Microsoft told the court the operation cost it more than $650,000. Investigators said a sloppy cryptocurrency wallet helped unmask the crew. Seized sites were swapped for warning pages. Paying customers migrated to new hosts, which is what PhaaS shops do when a brand gets burned.
Nigeria Police Force spokesman Benjamin Hundeyin said the December arrests grew out of intelligence from Microsoft, the FBI, and the U.S. Secret Service. Searches produced laptops, phones, and other devices. Samuel is accused of running the Telegram sales channel and hosting fake portals on Cloudflare with stolen or fraudulently obtained email accounts, according to The Hacker News. En senere nigeriansk presse konto også placeret Joshua Ogundipe og James Ogundipe i tidligere Lagos og Edo operationer i september og oktober 2025, som kun uddyber spørgsmålet om, hvorfor Samuel var navnet, der landede i december erklæring som den vigtigste udvikler.
Hvad en stjålet Microsoft 365 postkasse er faktisk værd
A captured Outlook session is not a trophy login. It is a quiet seat inside payroll, vendor invoices, patient charts, and student records. Microsoft documented an April 2025 tax-themed blast that hit more than 2,300 U.S. organizations. At least 20 hospitals and healthcare providers were among the victims. From there the path is familiar: mailbox monitoring, internal phishing that looks like it came from a coworker, then ransomware. The same vendor-risk logic showed up in The AEGIS Alliance reporting on the 700Kreditbrud, der afslørede næsten 6 millioner bilkøbere og Mixpanel hændelse, der sætter Pornhub Premium analytics i spil.
Commissioner of Police Ifeanyi Uche, who heads the National Cybercrime Centre, told users not to treat unexpected login prompts as routine. Hundeyin warned that campaigns like this produced business email compromise, data theft, and losses across several countries. The kit did not need a zero-day. It needed a person who would type a password into a page that looked like Microsoft.
Abuja afgifter og en Manhattan docket, der ikke deler en sagsøgt liste
Samuel faces identity theft, illegal access, and distribution of malicious software under Nigeria’s Cybercrimes Act of 2024. Early reporting put a preliminary Lagos High Court date around February 3, 2026. The FBI separately sought extradition of the alleged mastermind under the Computer Fraud and Abuse Act. Nigerian authorities were also said to have frozen accounts worth about 250 million naira, on the order of $550,000, while mapping money mules and mixers.
Public reporting through early September 2026 did not show a completed U.S. extradition of Ogundipe or a final Nigerian conviction of Samuel. Microsoft’s New York judgment does not, by itself, put anyone in a Lagos dock. That is why the FBI-Secret Service-NCCC channel matters more than the press release. A civil seizure can take domains. It cannot serve a warrant in Benin City.
Relateret Hacker-nyheder på dette skrivebord har sporet det samme mønster i andre grænseoverskridende sager, herunder den senere fil om hvordan De amerikanske finansstationer blev fjernadgangPhishing kits rejser hurtigere end gensidig juridisk bistand traktater.
Hvad der faktisk stopper dette produkt
Password-plus-SMS multi-factor authentication is what RaccoonO365 was built to steal. Passkeys and hardware security keys are harder for an adversary-in-the-middle page to replay. Check the URL before a password goes in. Report the message to IT instead of clicking “verify account.” Those habits are dull. They are also the reason a $355 Telegram subscription stops being a business.
A PhaaS shop that sells to clients on several continents will not be closed by one country. The National Cybercrime Centre now treats that cooperation as policy, not a one-off favor. The open question is whether the next kit keeps the Raccoon name or just changes the sticker on the same proxy. Until Samuel’s case is tried and Ogundipe is either produced or formally written off, the disruption is a pause, not a funeral.
Læsere, der ønsker bredere beat kan starte med AEGIS Alliance teknologi og internationale nyheder skriveborde. Det var billigt. Det var ikke postkassen, den åbnede.









