Microsoft seizes US-based infrastructure and websites used by cybercrime group Storm-1152 that created ~750M fraudulent Microsoft accounts, after a court order
Relying on a court order, the tech giant seized websites belonging to a top purveyor of fraudulent Microsoft accounts.
Context & Ripple Effects
Microsoft has repeatedly used court-authorized domain seizures to disrupt alleged threat actors, including its 2019 takeover of 99 sites tied to Phosphorus and 2021 seizure of 42 domains allegedly linked to a Chinese espionage group.
This case applies that legal-and-technical playbook to fraudulent-account infrastructure rather than a named espionage campaign. The reported scale makes account creation itself the operational asset being targeted, not merely a single phishing or command-and-control endpoint.
First-order effects
- Storm-1152 loses control of the US-based websites and infrastructure covered by the order, interrupting its ability to use those assets to supply fraudulent Microsoft accounts.
- Microsoft can remove or redirect the seized assets while reducing an identified source of account abuse against its services.
Second-order effects
- Operators dependent on this supply of fraudulent accounts may face short-term disruption and seek replacement domains, hosting, or account-creation channels.
- The action raises the value of rapid infrastructure attribution and legal coordination for platform defenders, because a court order can turn identified web assets into an immediate disruption point.
Third-order effects
- If this pattern continues, major platforms will increasingly pair account-abuse detection with civil seizure actions, extending private-sector disruption from espionage infrastructure to cybercrime supply chains.
- The approach can impose recurring replacement costs on operators, but its durability depends on whether enforcement can keep pace as groups shift infrastructure across jurisdictions.
The trend: Platform security is moving toward coordinated legal-and-technical takedowns that target the infrastructure enabling cybercrime at scale.