Hacker NewsInternational NewsNewsOther VideosVideos

Nigeria Holds Alleged RaccoonO365 Developer While Microsoft’s New York Suit Names a Different Ringleader

Operation Trashpanda: Disrupting RaccoonO365

Microsoft’s Digital Crimes Unit spent September 2025 seizing domains. Nigeria’s National Cybercrime Centre spent December 2025 booking a man whose name was not on Microsoft’s civil complaint. Those two timelines do not line up, and that mismatch is now the live part of the RaccoonO365 file.

Officers in Lagos and Edo States detained Okitipi Samuel, also known as Moses Felix and RaccoonO365, as the alleged developer of a phishing-as-a-service kit that sold counterfeit Microsoft 365 login pages for cryptocurrency. Two other people taken in the same sweeps were later released. Police said they found no evidence those two built or ran the platform. The man Microsoft had already sued in New York as the ringleader, Joshua Ogundipe of Benin City, was not named in the Nigerian police statement that followed the raids. Microsoft had referred him for international prosecution. His public whereabouts stayed unclear.

That split is not a footnote. It is the reason a domain seizure in Manhattan and a booking sheet in Lagos can both be true and still leave the shop’s alleged architect off camera.

A subscription desk, not a lone basement hacker

RaccoonO365 was merchandised like software-as-a-service. Operators charged about $355 for 30 days and $999 for 90 days, payable only in crypto. Buyers received generated pages that copied Microsoft, DocuSign, SharePoint, Adobe, and Maersk sign-in screens. Finance, human resources, and invoice themes filled the rest of the lure. Telegram channels tied to the shop counted more than 850 members. Recorded crypto payments topped $100,000. Senders could hit as many as 9,000 targets in a day.

Researchers say the service ran from at least July 2024 and harvested more than 5,000 Microsoft 365 credentials across 94 countries. The technical trick was an adversary-in-the-middle proxy. The fake page talked to Microsoft’s real servers, so the kit could lift passwords, multi-factor codes, and live session cookies in one pass. Cloudflare Turnstile CAPTCHA screens made the pages look like ordinary corporate gates. Cloudflare later said the customer base was mainly Russia-based crews. By late 2025 the operators were pitching an add-on called RaccoonO365 AI-MailCheck, a filter meant to score which stolen mailboxes were worth keeping.

Microsoft tracks the crew as Storm-2246. In April 2026, Digital Crimes Unit investigators described the September disruption under the internal name Operation Trashpanda, walking through how branding, Telegram sales, and AI-assisted targeting lowered the cost of entry for people who could not write an exploit themselves. Details of the Nigerian probe were first laid out by The Record and BleepingComputer.

Three hundred thirty-eight domains came down first

The police work followed a civil and technical takedown. Microsoft’s Digital Crimes Unit, Cloudflare’s Cloudforce One team, and Chainalysis used an order from the U.S. District Court for the Southern District of New York to seize 338 domains in September 2025. Microsoft and Health-ISAC sued Ogundipe and four John Does under the Computer Fraud and Abuse Act, RICO, and the Electronic Communications Privacy Act. Microsoft told the court the operation cost it more than $650,000. Investigators said a sloppy cryptocurrency wallet helped unmask the crew. Seized sites were swapped for warning pages. Paying customers migrated to new hosts, which is what PhaaS shops do when a brand gets burned.

Nigeria Police Force spokesman Benjamin Hundeyin said the December arrests grew out of intelligence from Microsoft, the FBI, and the U.S. Secret Service. Searches produced laptops, phones, and other devices. Samuel is accused of running the Telegram sales channel and hosting fake portals on Cloudflare with stolen or fraudulently obtained email accounts, according to The Hacker News. A later Nigerian press account also placed Joshua Ogundipe and James Ogundipe in earlier Lagos and Edo operations in September and October 2025, which only deepens the question of why Samuel was the name that landed in the December statement as the principal developer.

What a stolen Microsoft 365 mailbox is actually worth

A captured Outlook session is not a trophy login. It is a quiet seat inside payroll, vendor invoices, patient charts, and student records. Microsoft documented an April 2025 tax-themed blast that hit more than 2,300 U.S. organizations. At least 20 hospitals and healthcare providers were among the victims. From there the path is familiar: mailbox monitoring, internal phishing that looks like it came from a coworker, then ransomware. The same vendor-risk logic showed up in The AEGIS Alliance reporting on the 700Credit breach that exposed nearly 6 million car buyers and the Mixpanel incident that put Pornhub Premium analytics in play.

Commissioner of Police Ifeanyi Uche, who heads the National Cybercrime Centre, told users not to treat unexpected login prompts as routine. Hundeyin warned that campaigns like this produced business email compromise, data theft, and losses across several countries. The kit did not need a zero-day. It needed a person who would type a password into a page that looked like Microsoft.

Abuja charges and a Manhattan docket that do not share a defendant list

Samuel faces identity theft, illegal access, and distribution of malicious software under Nigeria’s Cybercrimes Act of 2024. Early reporting put a preliminary Lagos High Court date around February 3, 2026. The FBI separately sought extradition of the alleged mastermind under the Computer Fraud and Abuse Act. Nigerian authorities were also said to have frozen accounts worth about 250 million naira, on the order of $550,000, while mapping money mules and mixers.

Public reporting through early September 2026 did not show a completed U.S. extradition of Ogundipe or a final Nigerian conviction of Samuel. Microsoft’s New York judgment does not, by itself, put anyone in a Lagos dock. That is why the FBI-Secret Service-NCCC channel matters more than the press release. A civil seizure can take domains. It cannot serve a warrant in Benin City.

Related hacker news on this desk has tracked the same pattern in other cross-border cases, including the later file on how U.S. Treasury workstations were remotely accessed. Phishing kits travel faster than mutual legal assistance treaties.

What actually stops this product

Password-plus-SMS multi-factor authentication is what RaccoonO365 was built to steal. Passkeys and hardware security keys are harder for an adversary-in-the-middle page to replay. Check the URL before a password goes in. Report the message to IT instead of clicking “verify account.” Those habits are dull. They are also the reason a $355 Telegram subscription stops being a business.

A PhaaS shop that sells to clients on several continents will not be closed by one country. The National Cybercrime Centre now treats that cooperation as policy, not a one-off favor. The open question is whether the next kit keeps the Raccoon name or just changes the sticker on the same proxy. Until Samuel’s case is tried and Ogundipe is either produced or formally written off, the disruption is a pause, not a funeral.

Readers who want the wider beat can start with The AEGIS Alliance technology and international news desks. The kit was cheap. The mailbox it opened was not.

Jeffrey Childers
Journalist, editor, cybersecurity and computer science expert, social media management, roofing contractor.

Articoli Correlati

Lascia un commento

Il tuo indirizzo email non sarà pubblicato. I campi obbligatori sono contrassegnati *

Pulsante per tornare all'inizio
Signup for our news and memes newsletters! 

Newsletter Form

Lists
close-link