Close Menu
TechTost
  • AI
  • Apps
  • Crypto
  • Fintech
  • Hardware
  • Media & Entertainment
  • Security
  • Startups
  • Transportation
  • Venture
  • Recommended Essentials
What's Hot

Tesla adds ‘ribs’, other stats to track how often drivers use Full Self-Driving software

Microsoft is working on yet another OpenClaw-like agent

X brings voice memos back to X Chat

Facebook X (Twitter) Instagram
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer
Facebook X (Twitter) Instagram
TechTost
Subscribe Now
  • AI

    Microsoft is working on yet another OpenClaw-like agent

    14 April 2026

    OpenAI has acquired AI personal finance startup Hiro

    14 April 2026

    Largest orbital computing cluster is open for business

    13 April 2026

    Anthropic restricts Mythos traffic to protect the Internet — or does Anthropic?

    12 April 2026

    Sam Altman responds to ‘inflammatory’ New Yorker article after his home was attacked

    12 April 2026
  • Apps

    X brings voice memos back to X Chat

    14 April 2026

    Avec’s Tinder-style email app lets you swipe through your inbox

    14 April 2026

    Roblox introduces ‘Kids’ and ‘Select’ accounts for age-appropriate access to games and chats

    13 April 2026

    You can now edit your comments on Instagram

    13 April 2026

    Meta AI app climbs to No. 5 in App Store after release of Muse Spark

    12 April 2026
  • Crypto

    British cryptographer Adam Back denies NYT report that he is Bitcoin creator Satoshi Nakamoto

    9 April 2026

    Hackers stole over $2.7 billion in crypto in 2025, data shows

    23 December 2025

    New report examines how David Sachs may benefit from Trump administration role

    1 December 2025

    Why Benchmark Made a Rare Crypto Bet on Trading App Fomo, with $17M Series A

    6 November 2025

    Solana co-founder Anatoly Yakovenko is a big fan of agentic coding

    30 October 2025
  • Fintech

    Cash app launches ‘pay later’ feature for P2P transfers

    3 April 2026

    Doss raises $55 million for AI inventory management that connects to ERP

    24 March 2026

    Despite stiff competition, Kalshi, Polymarket CEOs back $35m VC fund projections

    23 March 2026

    Amid legal turmoil, Kalshi is temporarily banned in Nevada

    20 March 2026

    Nominations for the Startup Battlefield 200 are still open

    19 March 2026
  • Hardware

    Amazon is ending support for older Kindle devices

    9 April 2026

    Intel signs Elon Musk’s Terafab chip project

    8 April 2026

    The Xiaomi 17 Ultra has some impressive extras that make taking photos really fun

    6 April 2026

    In Japan, the robot doesn’t come for your job. fills the one no one wants

    6 April 2026

    Peter Thiel’s big bet on solar-powered cow collars

    5 April 2026
  • Media & Entertainment

    X says he’s reducing payouts to clickbait accounts

    12 April 2026

    TechCrunch is headed to Tokyo — and it’s bringing the Startup Battlefield with it

    10 April 2026

    Spotify now allows everyone to turn off videos in its app

    9 April 2026

    As YouTube expands into TV, it sees more interactive video across all formats

    9 April 2026

    Tubi is the first streamer to launch a native app on ChatGPT

    8 April 2026
  • Security

    Anodot hack leaves over a dozen compromised companies facing extortion

    14 April 2026

    Booking.com confirms that hackers accessed customer data

    13 April 2026

    Convicted spyware maker Bryan Fleming avoids jail time on conviction

    12 April 2026

    The Trump administration plans to cut the cybersecurity agency’s budget by $700 million

    11 April 2026

    Russian government hackers broke into thousands of home routers to steal passwords

    11 April 2026
  • Startups

    Walmart-owned Flipkart, Amazon are squeezing India’s e-commerce startups

    12 April 2026

    This founder helped build SpaceX’s most powerful rocket engine. Now he’s building a “fighter for orbit.”

    12 April 2026

    Sierra’s Bret Taylor says the era of button-clicking is over

    11 April 2026

    After the data breach, the $10 billion startup Mercor is one month old

    11 April 2026

    What founders can learn from Anjuna’s layoffs and recovery

    10 April 2026
  • Transportation

    Tesla adds ‘ribs’, other stats to track how often drivers use Full Self-Driving software

    14 April 2026

    Uber and Nuro begin testing premium robotaxi service in San Francisco

    14 April 2026

    Slate Auto raises $650 million to fund its affordable EV truck plans

    13 April 2026

    TechCrunch Mobility: Who’s chasing all the self-driving talent?

    13 April 2026

    Slate Auto: Everything you need to know about the Bezos-backed EV startup

    12 April 2026
  • Venture

    Vercel CEO Guillermo Rauch signals IPO readiness as AI agents drive revenue

    14 April 2026

    Nvidia-backed SiFive hits $3.65 billion valuation for open AI chips

    11 April 2026

    How to make the Startup Battlefield Top 20 — and what each company gets regardless

    10 April 2026

    Collide Capital Raises $95M to Back Future-of-Work Fintech Startups

    9 April 2026

    VC Eclipse has a new $1.3 billion fund to back — and build — “natural AI” startups

    8 April 2026
  • Recommended Essentials
TechTost
You are at:Home»Security»Microsoft disrupts cybercrime business by selling fraudulent accounts to notorious hacking gang
Security

Microsoft disrupts cybercrime business by selling fraudulent accounts to notorious hacking gang

techtost.comBy techtost.com15 December 202304 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email
Microsoft Disrupts Cybercrime Business By Selling Fraudulent Accounts To Notorious
Share
Facebook Twitter LinkedIn Pinterest Email

Microsoft says it has successfully dismantled the infrastructure of a cybercrime operation that sold access to fraudulent Outlook accounts to other hackers, including the notorious Scattered Spider gang.

The group, tracked by Microsoft as “Storm-1152”, is described as a major player in the cybercrime-as-a-service (CaaS) ecosystem, where criminals provide hacking and cybercrime services to other individuals or groups. Storm-1152 created approximately 750 million fraudulent Microsoft accounts for sale through the “hotmailbox.me” service to earn “millions of dollars in illegal revenue” and cause “millions of dollars in damage to Microsoft,” according to the company. The tech giant described the business as “the number one seller and creator of fraudulent Microsoft accounts.”

Microsoft described this feature as “a scheme to use Internet ‘bots’ to breach and trick Microsoft’s security systems into thinking they are legitimate consumers of Microsoft services, open Microsoft Outlook email accounts under fictitious user names and sell these fraudulent accounts to cybercriminals.”

The group also operated rate solving services for CAPTCHAs, including “1stCAPTCHA,” “AnyCAPTCHA,” and “NoneCAPTCHA,” according to Microsoft. Storm-1152 promoted these solvers as a way to bypass any type of CAPTCHA, allowing fraudsters to abuse the online environments of Microsoft and businesses in other industries.

Microsoft said it had identified several ransomware and extortion groups using Storm-1152’s services, including Octo Tempest, better known as Scattered Spider. Scattered Spider, a now-infamous hacking group believed to be made up of young English-speaking members, was linked earlier this year to a spree of attacks targeting Okta customers in an attempt to extract sensitive data. The group also claimed responsibility for the attack on MGM Resorts that will cost the hotel and casino giant about $100 million.

Microsoft told one court order received on Dec. 7 that its investigation into Storm-1152 revealed that Scattered Spider hackers had also recently carried out “massive ransomware attacks against top Microsoft customers,” resulting in service outages that caused hundreds of millions of dollars in damage.

Storm-1152’s services have also been used by cybercriminal groups “to harm not only Microsoft, but many other technology companies such as X (formerly Twitter) and Google and their customers,” according to the complaint. Google did not immediately respond to TechCrunch’s questions. A message sent to X’s guy’s email got an automated reply: “Busy now, check back later.”

Microsoft announced on Wednesday that it has successfully seized the infrastructure and domains of US-based Storm-1152 after receiving a court order from the Southern District of New York. These measures included seizing hotmailbox.me and stopping services such as 1stCAPTCHA, AnyCAPTCHA and NoneCAPTCHA, as well as targeting social media accounts used by Storm-1152 to promote these services.

The company said it had also identified the people behind Storm-1152’s operations. Those individuals, named Duong Dinh Tu, Linh Van Nguyễn (also known as Nguyễn Van Linh) and Tai Van Nguyen, are based in Vietnam, according to Microsoft.

“With our action today, our goal is to prevent criminal behavior,” said April Hogan-Burney, general manager of Microsoft’s Digital Crimes Unit. “By trying to slow the speed at which cybercriminals launch their attacks, we aim to increase their cost of doing business while we continue our investigation and protect our customers and other online users.”

Microsoft was helped to take down Storm-1152 by San Francisco-based cybersecurity firm Arkose Labs, which said it had been monitoring the operation since August 2021.

“Storm-1152 is a formidable enemy created with the sole purpose of making money by enabling adversaries to carry out sophisticated attacks,” Kevin Gosschalk, founder and CEO of Arkose Labs, said in a statement sent to TechCrunch. “The group is distinguished by the fact that it built its CaaS business in daylight versus the dark web. Storm-1152 acted as a standard online office, providing training on its tools and even full customer support. In effect, Storm-1152 was an unlocked gateway to serious fraud.’

Accounts business cyber security cybercrime disrupts fraudulent Gang hacker Hacking Microsoft notorious selling
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleHere are the best options for raising capital for late-stage startups
Next Article Google debuts Imagen 2 with text and logo creation
bhanuprakash.cg
techtost.com
  • Website

Related Posts

Microsoft is working on yet another OpenClaw-like agent

14 April 2026

Anodot hack leaves over a dozen compromised companies facing extortion

14 April 2026

Booking.com confirms that hackers accessed customer data

13 April 2026
Add A Comment

Leave A Reply Cancel Reply

Don't Miss

Tesla adds ‘ribs’, other stats to track how often drivers use Full Self-Driving software

14 April 2026

Microsoft is working on yet another OpenClaw-like agent

14 April 2026

X brings voice memos back to X Chat

14 April 2026
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Fintech

Cash app launches ‘pay later’ feature for P2P transfers

3 April 2026

Doss raises $55 million for AI inventory management that connects to ERP

24 March 2026

Despite stiff competition, Kalshi, Polymarket CEOs back $35m VC fund projections

23 March 2026
Startups

Walmart-owned Flipkart, Amazon are squeezing India’s e-commerce startups

This founder helped build SpaceX’s most powerful rocket engine. Now he’s building a “fighter for orbit.”

Sierra’s Bret Taylor says the era of button-clicking is over

© 2026 TechTost. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Type above and press Enter to search. Press Esc to cancel.