Storm-1152
- Origin
- VN
- Primary motivation
- financial-gain
- Sophistication
- expert
- Resource level
- organization
- Actor type
- criminal
- Profile updated
- 2026-07-07 12:13:12
Targeted industries: technology-and-telecommunications financial-services
Context
Storm-1152, a cybercriminal group, was recently taken down by Microsoft for illegally reselling Outlook accounts. They operated by creating approximately 750 million fraudulent Microsoft accounts and earned millions of dollars in illicit revenue. Storm-1152 also offered CAPTCHA-solving services and was connected to ransomware and extortion groups. Microsoft obtained a court order to seize their infrastructure and domains, disrupting their operations.
Reports & references
- rewterz.com — Rewterz Threat Update Microsoft Warns Of Emerging Threat By Storm 0539 Behind Gift Card Frauds (report)
- securityboulevard.com — Microsoft Storm 1152 Crackdown Stopping Threat Actors (report)
- Microsoft — Cybercrime Cybersecurity Storm 1152 Fraudulent Accounts (report)
- raw.githubusercontent.com — Microsoftmapping (report)