Microsoft seizes 338 websites to disrupt rapidly growing ‘RaccoonO365’ phishing service

Microsoft’s Digital Crimes Unit (DCU) has disrupted RaccoonO365, the fastest-growing tool used by cybercriminals to steal Microsoft 365 usernames and passwords (“credentials”). Using a court order granted by the Southern District of New York, the DCU seized 338 websites associated with the popular service, disrupting the operation’s technical infrastructure and cutting off criminals’ access to victims. This case shows that cybercriminals don’t need to be sophisticated to cause widespread harm—simple tools like RaccoonO365 make cybercrime accessible to virtually anyone, putting millions of users at risk.
While RaccoonO365 services are used to target all industries, as evidenced by an extensive tax-themed phishing campaign targeting over 2,300 organizations in the United States, most alarmingly, its kits have been used against at least 20 U.S. healthcare organizations. This puts public safety at risk, as RaccoonO365 phishing emails are often a precursor to malware and ransomware, which have severe consequences for hospitals. In these attacks, patient services are delayed, critical care is postponed or canceled, lab results are compromised, and sensitive data is breached, causing major financial losses and directly impacting patients. These severe consequences are a key reason why the DCU is filing this lawsuit in partnership with Health-ISAC—a global non-profit focused on cybersecurity and threat intelligence for the health sector.
Link to the Microsoft blog. Click Here
Link to the legal filings. Click Here
- Related Resources & News
- Healthcare finance trends for 2026: A mid-year update
- Threat Actor Playbook: Conversational Social Engineering in Care Settings
- The Human Risk Layer of AI
- Cybersecurity in the Lab
- Operation Vital Signs: First-of-its-kind exercise stress tests health sector cyber resilience
- What’s in America’s Code?
- Introducing AI Agents to Your Identity Fabric
- Cyberattacks on Healthcare Sector Jumped 14% in First Half of 2026
- What do cybersecurity leaders want in staff? These 3 skills beat certifications and experience
- Continuous attack surface monitoring and sophisticated social engineering assessment