/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Microsoft uncovers a massive phishing operation offering “Phishing-as-a-Service” subscriptions or one-time tools based on over 120 templates for $80-$100

Microsoft's security team said today that it uncovered a massive operation that provides phishing services to cybercrime gangs using … Source: Microsoft Security Blog .

The Record Catalin Cimpanu

Context & Ripple Effects

Microsoft's disclosure lands two years after Group-IB documented the phishing kit market already professionalizing, with average prices up 149% and seller counts up 120% in 2019 — this operation pushes one step further, packaging 120-plus templates into subscriptions or one-time purchases at $80–$100. It sits alongside earlier evidence of a mature resale market for compromised Microsoft identities, including C-level Office 365 accounts sold for $100–$1,500.

The significance is what came after: the template-and-subscription model Microsoft exposed became durable infrastructure, powering a campaign that [[a:980753|hijacked Office 365 authentication even on MFA-protected accounts across 10K+ organizations]] and surviving long enough to draw repeated Europol-coordinated takedowns of successor platforms.

First-order effects

  • Cybercrime gangs gain turnkey phishing capability at commodity pricing — no infrastructure or design skill required, just an $80–$100 subscription — while Microsoft's threat-intelligence team acquires visibility into the operator base and tooling that later fed joint operations like the LabHost takedown with Europol and 19 countries.

Second-order effects

  • Identity providers are forced onto a defensive treadmill: once rented kits industrialize delivery, attackers pivot to defeating controls rather than evading detection, as seen when Microsoft later warned about OAuth apps misused to automate phishing and the 10K-org MFA-bypass campaign.
  • Low-cost subscriptions compress the marginal cost of attack below the cost of per-account defense, pushing buyers toward bundled, platform-level protection — Microsoft's own ecosystem — rather than point tools.

Third-order effects

  • Phishing-as-a-service entrenches as a criminal SaaS category whose resilience shows in the pattern itself: disrupting LabHost in 2024 did not end the model, and by 2026 Europol was back dismantling Tycoon2FA, tied to tens of millions of monthly messages — implying deterrence now requires recurring multinational operations, not one-off arrests.
  • If subscription economics keep lowering attacker entry costs, the structural burden shifts to identity-layer hardening and vendor-led ecosystem defense, making the security posture of platform owners like Microsoft the de facto perimeter.

The trend: Phishing is industrializing from ad-hoc kit sales into resilient subscription platforms, countered by a matching escalation toward recurring, vendor-supported multinational takedowns.

Discussion

  • @tomwarren Tom Warren on x
    hopefully Microsoft's discovery will help improve @Outlook phishing email detection, which still allows emails like this to hit my inbox daily https://twitter.com/... https://twitter.com/...