Microsoft has dismantled 338 domains tied to RaccoonO365, a subscription-based phishing service linked to Nigerian operator Joshua Ogundipe. The platform sold phishing kits that bypassed MFA, stealing at least 5,000 Microsoft 365 credentials across 94 countries. Despite a U.S. court order, Ogundipe remains free abroad. Cloudflare also blocked related infrastructure, as the scheme increasingly targeted U.S. businesses, healthcare groups, and even launched AI-powered attack tools.
