Developer behind the RaccoonO365 phishing service arrested in Nigeria
Nigerian police have arrested three people for internet fraud, among them the alleged developer of the RaccoonO365 phishing-as-a-service kit. The force's national cybercrime centre, working with Microsoft and the FBI, identified Okitipi Samuel, also known as Moses Felix, as the principal operator of the infrastructure. He is said to have run a Telegram channel selling phishing links for cryptocurrency and to have hosted fraudulent Microsoft login portals. Raids in Lagos and Edo states seized equipment. Microsoft tracks the activity as Storm-2246 and links it to at least 5,000 compromised Microsoft credentials across 94 countries since July 2024, leading to business email compromise, data breaches and financial losses. In September 2025 Microsoft and Cloudflare seized 338 domains used by the kit.
What this means for your organisation
The arrest removes one supplier, not the demand. Phishing as a service means actors with no technical skill can buy ready-made attacks against Microsoft 365. Your defence is access control, not the pace of law enforcement.
Berigo recommends
- Deploy phishing-resistant multi-factor authentication across all Microsoft 365 accounts.
- Check whether any of your accounts appear in known credential leaks, and rotate those passwords.
- Detect forwarding rules and unusual sign-ins, the classic markers of business email compromise.
- Establish a payment routine where any change of account number is verified in a separate channel.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch