The phishing operation ended up stealing at least 5,000 Microsoft user credentials. The service enables users to impersonate trusted brand names and get targets to enter Microsoft login details on fake Microsoft platforms. Raccoon0365 users targeted a wide range of industries, a significant number of which are organizations based in New York City, Masada said. Raccoon0365 operators used Cloudflare services to help conceal the service’s backend infrastructure. Blake Darche, the head of threat intelligence at Cloudflare, said that while Raccoon0365 operators made some operational security mistakes, they were highly effective.