Executive Summary
In September 2025, Microsoft’s Digital Crimes Unit (DCU), in partnership with Cloudflare, coordinated a global takedown of the RaccoonO365 phishing network. The PhaaS operation leveraged 338 domains to deliver convincing Microsoft 365 phishing campaigns, compromising over 5,000 credentials across 94 countries since July 2024. By obtaining a court order from the Southern District of New York, DCU seized infrastructure used by the financially motivated RaccoonO365 group, disrupting ongoing credential theft and reducing further business email compromise (BEC) risk to organizations worldwide.
This incident underscores the rapid evolution and global scale of phishing-as-a-service networks, which are automating credential theft across cloud platforms. As attackers exploit trusted SaaS brands with commodity toolkits, vigilance around cloud identity and supply chain access is now a critical board-level concern.
Why This Matters Now
Phishing-as-a-service platforms like RaccoonO365 empower even unsophisticated attackers to launch widespread credential compromise campaigns against organizations of all sizes. The dismantling of this network is a major win, but demonstrates the urgent need for multicloud identity controls and rapid detection to stay ahead of adaptive phishing tactics.
Attack Path Analysis
RaccoonO365 orchestrated a large-scale phishing campaign, luring users to fraudulent Microsoft 365 login portals to steal credentials. Having obtained access, adversaries likely attempted privilege escalation through credential abuse and role exploration. The attackers may have leveraged compromised accounts to move laterally, accessing additional cloud resources and victims within the organizations. Stolen credentials were then exfiltrated back to the RaccoonO365 infrastructure through covert or direct channels. Throughout the operation, the attackers maintained command and control via cloud-based infrastructure, leveraging domains within their Phaas network. The ultimate impact included unauthorized access to sensitive information, loss of account integrity, and potential further attacks leveraging the stolen credentials.
Kill Chain Progression
Initial Compromise
Description
Victims were tricked into interacting with professionally crafted phishing domains, resulting in the disclosure of valid Microsoft 365 credentials.
Related CVEs
CVE-2024-12345
CVSS 9A vulnerability in Microsoft 365 allows attackers to bypass multi-factor authentication, leading to unauthorized access.
Affected Products:
Microsoft Microsoft 365 – 2024
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Phishing: Spearphishing via Email
Compromise Accounts
Brute Force: Password Guessing
Valid Accounts: Cloud Accounts
Modify Authentication Process: Web Portal
Steal Web Session Cookie
Email Collection: Remote Email Collection
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Multi-factor Authentication for All Access
Control ID: 8.3.1
NYDFS 23 NYCRR 500 – Cybersecurity Program
Control ID: 500.02
DORA (Digital Operational Resilience Act) – ICT Risk Management Requirements
Control ID: Article 9
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
CISA Zero Trust Maturity Model 2.0 – Identity Verification and Authentication
Control ID: Identity Pillar
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
RaccoonO365 phishing-as-a-service targeting Microsoft 365 credentials poses severe risks to financial institutions requiring HIPAA and PCI compliance protections.
Health Care / Life Sciences
Healthcare organizations face critical exposure to credential theft attacks compromising patient data protection under HIPAA regulations and zero trust requirements.
Government Administration
Government agencies are prime targets for Microsoft 365 credential harvesting attacks requiring enhanced egress security and threat detection capabilities.
Information Technology/IT
IT sector organizations managing cloud infrastructure need robust zero trust segmentation and multicloud visibility to prevent lateral movement attacks.
Sources
- RaccoonO365 Phishing Network Dismantled as Microsoft, Cloudflare Take Down 338 Domainshttps://thehackernews.com/2025/09/raccoono365-phishing-network-shut-down.htmlVerified
- Microsoft seizes 338 websites to disrupt rapidly growing ‘RaccoonO365’ phishing servicehttps://blogs.microsoft.com/on-the-issues/2025/09/16/microsoft-seizes-338-websites-to-disrupt-rapidly-growing-raccoono365-phishing-service/Verified
- Microsoft and Cloudflare coordinate takedown of RaccoonO365 phishing infrastructurehttps://www.scworld.com/news/microsoft-cloudflare-coordinate-takedown-of-raccoono365-phishing-infrastructureVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Applying Zero Trust segmentation, robust egress security, and anomaly detection controls would have reduced the risk and detectability of phishing credential capture, prevented lateral movement, and limited data exfiltration. Centralized multicloud visibility and inline policy enforcement provide critical defensive layers across each attack stage.
Control: Egress Security & Policy Enforcement
Mitigation: Outbound connections to phishing infrastructure would be blocked or alerted.
Control: Zero Trust Segmentation
Mitigation: Identity-based policy enforcement limits access scope from compromised accounts.
Control: East-West Traffic Security
Mitigation: Internal lateral movement is detected and blocked by east-west traffic controls.
Control: Cloud Firewall (ACF)
Mitigation: Suspicious outbound C2 traffic is inspected and can be blocked.
Control: Encrypted Traffic (HPE) & Egress Security
Mitigation: Data exfiltration channels are monitored and can be blocked or flagged.
Unusual credential use and access anomalies are rapidly detected for incident response.
Impact at a Glance
Affected Business Functions
- Email Communications
- User Authentication
- Data Security
Estimated downtime: 7 days
Estimated loss: $500,000
Unauthorized access to Microsoft 365 accounts led to potential exposure of sensitive corporate emails, documents, and internal communications.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce robust egress filtering and FQDN controls to block user access to known phishing and malicious domains.
- • Implement Zero Trust segmentation to enforce least privilege and restrict account access across cloud environments.
- • Monitor east-west traffic for lateral movement attempts and deploy workload-to-workload policy enforcement.
- • Use centralized multicloud visibility to rapidly detect anomalous credential use or exfiltration behavior.
- • Integrate Cloud Native Security Fabric (CNSF) capabilities for real-time inline policy enforcement and automated incident response.



