{ "@context": "https://schema.org", "@type": "NewsArticle", "headline": "RaccoonO365 Phishing Network Dismantled: Microsoft & Cloudflare Seize 338 Domains", "datePublished": "2026-08-13T12:00:00+05:30", "dateModified": "2026-08-13T12:00:00+05:30", "author": { "@type": "Person", "name": "Jai" }, "publisher": { "@type": "Organization", "name": "Veritya Daily", "logo": { "@type": "ImageObject", "url": "https://verityadaily.com/assets/img/logo.png" } }, "image": "https://verityadaily.com/assets/img/og-image.png", "description": "Microsoft Digital Crimes Unit and Cloudflare seized 338 domains used by the RaccoonO365 phishing-as-a-service toolkit, which stole 5,000+ Microsoft 365 credentials from 94 countries.", "mainEntityOfPage": "https://verityadaily.com/raccoono365-takedown", "inLanguage": "en-US", "isAccessibleForFree": true, "thumbnailUrl": "https://verityadaily.com/assets/img/hero-raccoono365-takedown.png" } { "@context":"https://schema.org", "@type":"FAQPage", "mainEntity":[ {"@type":"Question","name":"What was RaccoonO365?","acceptedAnswer":{"@type":"Answer","text":"RaccoonO365 was a phishing-as-a-service toolkit that allowed cybercriminals to create convincing Microsoft 365 login pages to steal credentials from victims across 94 countries."}}, {"@type":"Question","name":"How many domains were seized in the RaccoonO365 takedown?","acceptedAnswer":{"@type":"Answer","text":"Microsoft Digital Crimes Unit and Cloudflare jointly seized 338 domains used by the RaccoonO365 phishing infrastructure."}}, {"@type":"Question","name":"How many credentials did RaccoonO365 steal?","acceptedAnswer":{"@type":"Answer","text":"The toolkit stole over 5,000 Microsoft 365 credentials from victims in 94 countries since July 2024."}} ] } { "@context": "https://schema.org", "@type": "BreadcrumbList", "itemListElement": [ {"@type": "ListItem", "position": 1, "name": "Home", "item": "https://verityadaily.com/"}, {"@type": "ListItem", "position": 2, "name": "Cybersecurity", "item": "https://verityadaily.com/category-cybersecurity"}, {"@type": "ListItem", "position": 3, "name": "RaccoonO365 Phishing Network Dismantled"} ] }
BTC $63,085 โ–ผ0.50% ETH $1,879 โ–ฒ0.28% SOL $75.22 โ–ฒ0.50% XRP $1.02 โ–ฒ0.90%
Cybersecurity

RaccoonO365 Phishing Network Dismantled

raccoono365 takedown

Key Takeaways

What Was RaccoonO365?

RaccoonO365 was a phishing-as-a-service (PhaaS) platform that provided cybercriminals with ready-made tools to steal Microsoft 365 login credentials. Rather than requiring technical expertise, the service offered a turnkey solution: subscribers could launch convincing phishing campaigns mimicking Microsoft 365 login pages with minimal effort.

The toolkit generated realistic-looking login portals that closely mirrored Microsoft's actual authentication pages. These fake pages captured usernames, passwords, and โ€” critically โ€” multi-factor authentication tokens, allowing attackers to bypass MFA protections that organizations had carefully implemented.

RaccoonO365 was active since at least July 2024, operating continuously for over two years before the takedown. The service evolved over time, updating its phishing templates to match Microsoft's design changes and incorporating new evasion techniques to bypass email security filters.

"RaccoonO365 made cybercrime accessible to virtually anyone โ€” no coding skills required, just a subscription and a list of email targets."

How the Phishing-as-a-Service Model Worked

The PhaaS model represented a dangerous evolution in cybercrime accessibility. Here's how RaccoonO365 operated:

The service essentially lowered the barrier to entry for credential theft. A would-be attacker didn't need to understand phishing page design, email spoofing, or credential harvesting โ€” RaccoonO365 handled all of that. This is why Microsoft described the operation as making "cybercrime accessible to virtually anyone."

PhaaS FeatureTraditional PhishingRaccoonO365
Technical skill requiredHighMinimal
Domain managementManualAutomated rotation
MFA bypassRareBuilt-in
Template updatesManualContinuous
Cost to attackerVariableSubscription fee

The Takedown: 338 Domains Seized

The coordinated takedown involved Microsoft's Digital Crimes Unit and Cloudflare, combining legal authority with technical infrastructure control. Microsoft obtained a court order allowing the seizure of 338 domains associated with RaccoonO365's infrastructure, and Cloudflare executed the technical steps to redirect those domains away from the phishing servers.

This wasn't a simple domain suspension. The 338 domains represented RaccoonO365's entire operational footprint โ€” the phishing pages, the redirect chains, the credential collection endpoints, and the management interfaces. By seizing all of them simultaneously, the operation dealt a crippling blow to the service's infrastructure.

The takedown also involved intelligence gathering. Microsoft's team analyzed the stolen credential data, identifying victim organizations and notifying affected parties. This post-takedown phase is critical: it's not enough to shut down the infrastructure โ€” affected organizations need to know their credentials were compromised so they can take remedial action.

Scale of the Damage: 5,000+ Credentials, 94 Countries

The numbers tell a sobering story. RaccoonO365 stole over 5,000 Microsoft 365 credentials from victims spread across 94 countries. Each stolen credential represents a potential entry point into an organization's email, files, and internal systems.

Microsoft 365 credentials are particularly valuable because they provide access to:

The geographic spread โ€” 94 countries โ€” demonstrates that PhaaS operations have global reach. No region was immune. Organizations in North America, Europe, Asia, Africa, and Latin America were all targeted, reflecting the indiscriminate nature of phishing campaigns launched through the platform.

Why This Takedown Matters

The RaccoonO365 takedown is significant for several reasons beyond the immediate disruption:

1. It disrupts the PhaaS supply chain. By seizing the entire domain infrastructure, the takedown doesn't just stop one campaign โ€” it disables the platform that enabled dozens or hundreds of campaigns by different attackers.

2. It demonstrates effective public-private partnership. Microsoft provided the threat intelligence and legal action, while Cloudflare provided the technical infrastructure control. This collaboration model is becoming the template for future takedowns.

3. It exposes the scale of credential theft. 5,000+ stolen credentials over two years represents a significant intelligence failure for affected organizations. Many likely didn't know their credentials were compromised until Microsoft notified them.

4. It highlights the MFA bypass problem. RaccoonO365's ability to capture MFA tokens means that MFA alone is no longer sufficient. Organizations need phishing-resistant authentication methods like FIDO2 hardware keys.

Phishing-as-a-service has commoditized credential theft. The only defense is phishing-resistant authentication โ€” not passwords, not SMS codes, not even authenticator apps.

Protecting Your Organization from Phishing-as-a-Service

The RaccoonO365 takedown is a wake-up call. Here's what organizations should do immediately:

The takedown of RaccoonO365 is a victory, but it's temporary. Other PhaaS platforms will emerge to fill the void. The long-term solution isn't playing whack-a-mole with phishing domains โ€” it's eliminating the password as an attack surface entirely through phishing-resistant authentication.

Jai

Cybersecurity journalist covering threat intelligence, data breaches, and law enforcement takedowns. Tracking the intersection of cybercrime and justice.