Microsoft uncovers a massive phishing operation offering “Phishing-as-a-Service” subscriptions or one-time tools based on over 120 templates for $80-$100
Microsoft's security team said today that it uncovered a massive operation that provides phishing services to cybercrime gangs using … Source: Microsoft Security Blog .
Context & Ripple Effects
Microsoft's disclosure lands two years after Group-IB documented the phishing kit market already professionalizing, with average prices up 149% and seller counts up 120% in 2019 — this operation pushes one step further, packaging 120-plus templates into subscriptions or one-time purchases at $80–$100. It sits alongside earlier evidence of a mature resale market for compromised Microsoft identities, including C-level Office 365 accounts sold for $100–$1,500.
The significance is what came after: the template-and-subscription model Microsoft exposed became durable infrastructure, powering a campaign that [[a:980753|hijacked Office 365 authentication even on MFA-protected accounts across 10K+ organizations]] and surviving long enough to draw repeated Europol-coordinated takedowns of successor platforms.
First-order effects
- Cybercrime gangs gain turnkey phishing capability at commodity pricing — no infrastructure or design skill required, just an $80–$100 subscription — while Microsoft's threat-intelligence team acquires visibility into the operator base and tooling that later fed joint operations like the LabHost takedown with Europol and 19 countries.
Second-order effects
- Identity providers are forced onto a defensive treadmill: once rented kits industrialize delivery, attackers pivot to defeating controls rather than evading detection, as seen when Microsoft later warned about OAuth apps misused to automate phishing and the 10K-org MFA-bypass campaign.
- Low-cost subscriptions compress the marginal cost of attack below the cost of per-account defense, pushing buyers toward bundled, platform-level protection — Microsoft's own ecosystem — rather than point tools.
Third-order effects
- Phishing-as-a-service entrenches as a criminal SaaS category whose resilience shows in the pattern itself: disrupting LabHost in 2024 did not end the model, and by 2026 Europol was back dismantling Tycoon2FA, tied to tens of millions of monthly messages — implying deterrence now requires recurring multinational operations, not one-off arrests.
- If subscription economics keep lowering attacker entry costs, the structural burden shifts to identity-layer hardening and vendor-led ecosystem defense, making the security posture of platform owners like Microsoft the de facto perimeter.
The trend: Phishing is industrializing from ad-hoc kit sales into resilient subscription platforms, countered by a matching escalation toward recurring, vendor-supported multinational takedowns.