Exposed: Nigerian Cybercrime Ring Nets $100K Via Fake Microsoft Sites!

Microsoft has successfully disrupted a sophisticated cybercrime operation, RaccoonO365, based in Nigeria. This phishing-as-a-service (PhaaS) platform generated over $100,000 by developing and leasing deceptive Microsoft 365 login pages to a global network of scammers. Since its inception in July 2024, RaccoonO365 facilitated the theft of login credentials through meticulously crafted phishing emails, malicious QR codes, and attachments that mimicked legitimate Microsoft branding and websites.
In a coordinated effort, Microsoft's Digital Crimes Unit (DCU), in collaboration with cybersecurity firm Cloudflare, undertook significant legal and technical action. This operation resulted in the seizure of 338 websites that were integral to RaccoonO365's activities. These sites were designed to perfectly replicate Microsoft login interfaces, making them highly effective in deceiving users.
The impact of RaccoonO365 was substantial, with more than 5,000 login credentials stolen from users across 94 countries. The compromised information was likely monetized through sales on dark web forums or utilized in subsequent fraudulent schemes, such as business email compromise (BEC), a particularly prevalent form of fraud in West Africa.
RaccoonO365 operated by advertising its phishing tools via an exclusive, invite-only Telegram channel that boasted over 850 members. The platform reportedly catered to between 100 and 200 active subscribers who paid for access to its comprehensive phishing kits. These kits were remarkably user-friendly, enabling subscribers to select specific targets, dispatch phishing links, and even monitor login attempts, effectively lowering the technical barrier for individuals wishing to engage in cybercrime.
While Microsoft's disruption is a significant victory for cybersecurity, experts caution that it likely represents only a temporary setback for the broader PhaaS ecosystem. This case further highlights a concerning trend of phishing attacks specifically targeting Nigerian tech startups, especially those managing sensitive HR and financial data. The incident underscores the critical need for enhanced cyber awareness in Nigeria, particularly given the country's gradual expansion of cloud infrastructure.
The broader context reveals a surge in cybercrime across Africa. The Nigerian Computer Emergency Response Team (ngCERT) has warned that cloud service providers based in Nigeria are susceptible to Phobos ransomware attacks. Scam notifications have seen an alarming increase of nearly 3,000% in key African nations like Zambia, Egypt, and Kenya, with phishing being the predominant method. For African businesses, particularly Small and Medium-sized Enterprises (SMEs) that rely heavily on Microsoft products, prioritizing cybersecurity is paramount as phishing operations become increasingly accessible and harder to detect.
You may also like...
Heat's Playoff Hopes Dented: Miami Falls to Raptors, Faces Play-In Gauntlet for Fourth Time

The Miami Heat are heading to the NBA play-in tournament for the fourth consecutive year, despite their expressed desire...
Wemby Scare: Spurs Star Victor Wembanyama Dodges Major Injury, Status Doubtful for Blazers Clash

San Antonio Spurs star Victor Wembanyama is doubtful for Wednesday's game due to a rib contusion, but is expected to pla...
Shocking Revelation: 'Euphoria' Creator Sam Levinson Drops Bombshells on Angus Cloud Loss and Season 4's Fate

"Euphoria" Season 3 faced immense challenges, including the deaths of Angus Cloud and Eric Dane's ALS diagnosis, with cr...
Exclusive: Norwegian Horror Sensation ‘You’ve Been Chosen’ Secures Global Distribution Deal at Cannes

Blue Finch Films is set to represent Viljar Bøe's psychological horror film "You've Been Chosen" as its worldwide sales ...
Daredevil Stars Tease [SPOILER]'s Pivotal Impact on Season 3
![Daredevil Stars Tease [SPOILER]'s Pivotal Impact on Season 3](https://static0.colliderimages.com/wordpress/wp-content/uploads/2026/04/daredevil-born-again-season-2-charlie-cox-vincent-d-onofrio-interview.jpg?w=1600&h=900&fit=crop)
The new season of Daredevil: Born Again sees Charlie Cox and Vincent D'Onofrio return as Daredevil and Kingpin, explorin...
Wilson Bethel Unlocks Bullseye's Most Unhinged 'Daredevil' Episode

Wilson Bethel delves into the mindset of Bullseye in "Daredevil: Born Again" Season 2, Episode 4, revealing the villain'...
Freed! American Journalist Returns Home After Iraq Abduction, Militants Released in Swap

American freelance journalist Shelly Kittleson has been released in Iraq a week after her abduction by the Iran-backed K...
World Holds Breath: Trump Declares Two-Week Ceasefire, Strait of Hormuz Reopens Amid Iran War Tensions

President Donald Trump announced a two-week ceasefire with Iran, averting a threatened devastating attack just hours bef...

