Microsoft seizes US-based infrastructure and websites used by cybercrime group Storm-1152 that created ~750M fraudulent Microsoft accounts, after a court order
Context & Ripple Effects
Microsoft has repeatedly used court-ordered domain seizures against cyber-espionage and state-linked groups, including an alleged Iranian-linked website network and Russia-linked infrastructure targeting Ukraine. This action applies the same private-sector legal disruption model to a cybercrime operation built around fraudulent account creation.
The scale of the affected account pipeline makes the case consequential for Microsoft’s identity systems: abuse infrastructure can be interrupted upstream, rather than addressed solely through account-by-account enforcement.
First-order effects
- Storm-1152 loses access to US-based infrastructure and websites used to create fraudulent Microsoft accounts, disrupting the operation’s immediate account-supply pipeline.
- Microsoft can take the targeted systems out of criminal control and use the seizure to support enforcement against abuse tied to those accounts.
Second-order effects
- Operators relying on Storm-1152’s account output may face higher friction or seek replacement infrastructure, while Microsoft must watch for migration to new domains and services.
- The action reinforces domain seizure as a complement to technical account-abuse controls, rather than a one-time substitute for them.
Third-order effects
- If such actions continue, large platforms’ identity defenses will increasingly combine product controls, threat intelligence, and court-backed infrastructure takedowns.
- The pattern may make durable disruption depend less on removing individual bad accounts and more on targeting the services that industrialize account fraud.
The trend: Platform security is shifting toward dismantling the infrastructure that scales identity abuse, using legal and technical controls together.