/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Microsoft seizes US-based infrastructure and websites used by cybercrime group Storm-1152 that created ~750M fraudulent Microsoft accounts, after a court order

CyberScoop AJ Vicens

Context & Ripple Effects

Microsoft has repeatedly used court-ordered domain seizures against cyber-espionage and state-linked groups, including an alleged Iranian-linked website network and Russia-linked infrastructure targeting Ukraine. This action applies the same private-sector legal disruption model to a cybercrime operation built around fraudulent account creation.

The scale of the affected account pipeline makes the case consequential for Microsoft’s identity systems: abuse infrastructure can be interrupted upstream, rather than addressed solely through account-by-account enforcement.

First-order effects

  • Storm-1152 loses access to US-based infrastructure and websites used to create fraudulent Microsoft accounts, disrupting the operation’s immediate account-supply pipeline.
  • Microsoft can take the targeted systems out of criminal control and use the seizure to support enforcement against abuse tied to those accounts.

Second-order effects

  • Operators relying on Storm-1152’s account output may face higher friction or seek replacement infrastructure, while Microsoft must watch for migration to new domains and services.
  • The action reinforces domain seizure as a complement to technical account-abuse controls, rather than a one-time substitute for them.

Third-order effects

  • If such actions continue, large platforms’ identity defenses will increasingly combine product controls, threat intelligence, and court-backed infrastructure takedowns.
  • The pattern may make durable disruption depend less on removing individual bad accounts and more on targeting the services that industrialize account fraud.

The trend: Platform security is shifting toward dismantling the infrastructure that scales identity abuse, using legal and technical controls together.

Discussion

  • @carlypage_ Carly Page on x
    Microsoft has disrupted Storm-1152, a cybercrime operation that sold fraudulent accounts to other groups, including Scattered Spider. It says Storm-1152's services have been used “to injure not just Microsoft” but also “X, Google and their customers” https://techcrunch.com/...
  • @sixdub Justin on x
    The Digital Crimes Unit (DCU)of Microsoft (w/Arkose Labs) has taken legal action against the individuals behind Storm-1152, the number one creator and seller of fraudulent Microsoft accounts. To date, Storm-1152 has created for sale ~750 million accts. https://blogs.microsoft.com…
  • @itsreallynick Nick Carr on x
    Watching the drastic impacts in real-time as the servers came down 🤌 Read more: https://blogs.microsoft.com/ ... [image]
  • @msftsecintel @msftsecintel on x
    Fraudulent online accounts act as the gateway to cybercrime, incl. phishing, identity theft & fraud, DDoS. Microsoft, w/ insights from Arkose Labs, is going after the number one seller & creator of fraudulent Microsoft accounts, a group we call Storm-1152: https://blogs.microsoft…