Nigerian authorities have arrested Okitipi Samuel, also known as Moses Felix, identified as a principal developer behind the RaccoonO365 phishing-as-a-service (PhaaS) operation. The arrest, conducted by the Nigeria Police Force National Cybercrime Centre (NPF–NCCC) in collaboration with Microsoft, the FBI, and the U.S. Secret Service, followed coordinated raids in Lagos and Edo states. Investigators seized laptops, mobile devices, and other digital equipment linked to the operation, and determined that Samuel operated a Telegram channel to sell phishing links for cryptocurrency and hosted fraudulent Microsoft 365 login portals on Cloudflare using stolen or fraudulently obtained credentials. Two other individuals were also arrested but were not connected to the creation or operation of the PhaaS service.
RaccoonO365 is a subscription-based phishing kit that enabled cybercriminals to create convincing Microsoft-branded phishing pages, emails, and attachments, facilitating credential harvesting attacks against corporate, financial, and educational institutions worldwide. The toolkit, tracked by Microsoft as Storm-2246, was used to target thousands of email addresses daily and included features to bypass multifactor authentication. In September 2025, Microsoft and Cloudflare collaborated to seize 338 domains associated with the operation, which is estimated to have compromised at least 5,000 Microsoft credentials across 94 countries since July 2024. The takedown highlights ongoing efforts by law enforcement and private sector partners to disrupt large-scale phishing infrastructure and the cybercriminal ecosystem supporting it.

Get the infrastructure and lures behind it.
6 events from the most recent confirmed update back to the earliest known activity.
Nigerian authorities arrested three internet fraud suspects, including Okitipi Samuel, also known as Moses Felix, who is believed to be the main developer of RaccoonO365. The arrests followed a joint investigation involving the Nigeria Police Force National Cybercrime Centre, Microsoft, the FBI, and reporting also cited the U.S. Secret Service.
Separately, Google filed lawsuits against operators of the Darcula and Lighthouse phishing-as-a-service platforms, including Chinese nationals, seeking to seize infrastructure used in large-scale smishing and phishing campaigns. These actions were reported alongside the RaccoonO365 case.
Microsoft and Health-ISAC filed a civil lawsuit against additional individuals accused of distributing the RaccoonO365 phishing kit. The legal action accompanied broader efforts to dismantle the phishing ecosystem behind the attacks.
The operators marketed the subscription-based phishing kit and phishing links through a Telegram channel with more than 800 members. The service used Cloudflare-hosted fraudulent Microsoft 365 login pages and was reportedly used heavily by Russia-based cybercriminals.
In September 2025, Microsoft and Cloudflare coordinated to seize domains and websites tied to the RaccoonO365 phishing service. The disruption targeted infrastructure used to host fake Microsoft 365 login portals and support credential theft operations.
Since July 2024, the RaccoonO365 phishing-as-a-service operation has stolen at least 5,000 Microsoft credentials across 94 countries. The kit was used to create fake Microsoft 365 login portals, enabling business email compromise, data breaches, and financial losses.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
3 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcetherecord.media
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.