/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Microsoft seizes US-based infrastructure and websites used by cybercrime group Storm-1152 that created ~750M fraudulent Microsoft accounts, after a court order

Relying on a court order, the tech giant seized websites belonging to a top purveyor of fraudulent Microsoft accounts.

CyberScoop AJ Vicens

Context & Ripple Effects

Microsoft has repeatedly used court-authorized domain seizures to disrupt alleged threat actors, including its 2019 takeover of 99 sites tied to Phosphorus and 2021 seizure of 42 domains allegedly linked to a Chinese espionage group.

This case applies that legal-and-technical playbook to fraudulent-account infrastructure rather than a named espionage campaign. The reported scale makes account creation itself the operational asset being targeted, not merely a single phishing or command-and-control endpoint.

First-order effects

  • Storm-1152 loses control of the US-based websites and infrastructure covered by the order, interrupting its ability to use those assets to supply fraudulent Microsoft accounts.
  • Microsoft can remove or redirect the seized assets while reducing an identified source of account abuse against its services.

Second-order effects

  • Operators dependent on this supply of fraudulent accounts may face short-term disruption and seek replacement domains, hosting, or account-creation channels.
  • The action raises the value of rapid infrastructure attribution and legal coordination for platform defenders, because a court order can turn identified web assets into an immediate disruption point.

Third-order effects

  • If this pattern continues, major platforms will increasingly pair account-abuse detection with civil seizure actions, extending private-sector disruption from espionage infrastructure to cybercrime supply chains.
  • The approach can impose recurring replacement costs on operators, but its durability depends on whether enforcement can keep pace as groups shift infrastructure across jurisdictions.

The trend: Platform security is moving toward coordinated legal-and-technical takedowns that target the infrastructure enabling cybercrime at scale.

Discussion

  • @itsreallynick Nick Carr on x
    Watching the drastic impacts in real-time as the servers came down 🤌 Read more: https://blogs.microsoft.com/ ... [image]
  • @sixdub Justin on x
    The Digital Crimes Unit (DCU)of Microsoft (w/Arkose Labs) has taken legal action against the individuals behind Storm-1152, the number one creator and seller of fraudulent Microsoft accounts. To date, Storm-1152 has created for sale ~750 million accts. https://blogs.microsoft.com…
  • @msftsecintel @msftsecintel on x
    Fraudulent online accounts act as the gateway to cybercrime, incl. phishing, identity theft & fraud, DDoS. Microsoft, w/ insights from Arkose Labs, is going after the number one seller & creator of fraudulent Microsoft accounts, a group we call Storm-1152: https://blogs.microsoft…