Nigeria Police Force National Cybercrime Centre (NPF–NCCC) has apprehended high-profile internet fraud suspects involved in targeted cyberattacks against the email systems of major corporate organisations through the deployment of phishing links and malicious software.
The Force spokesman, CSP Benjamin Hundeyin, confirmed this in a statement issued on Thursday in Abuja.
CSP Hundeyin said the significant breakthrough followed credible and actionable intelligence received from Microsoft Corporation, United States of America, through the Federal Bureau of Investigation (FBI), which revealed the use of a sophisticated phishing toolkit known as RaccoonO365.
He said the toolkit was designed to create fraudulent Microsoft login portals aimed at harvesting user credentials and unlawfully accessing the email platforms of corporate, financial, and educational institutions.
“Consequently, the NPF–NCCC initiated a coordinated, intelligence-driven operation in collaboration with Microsoft, the FBI, and the United States Secret Service.
” Investigations traced multiple incidents of unauthorised Microsoft 365 account access between January and September 2025 to phishing emails crafted to closely mimic legitimate Microsoft authentication pages”.
“These activities resulted in business email compromise, data breaches, and financial losses across multiple jurisdictions”, he said.
According to him, acting on precise and actionable intelligence, NPF–NCCC operatives were deployed to Lagos and Edo States, leading to the arrest of three suspects.
“Search operations conducted at their residences resulted in the recovery of laptops, mobile devices, and other digital equipment, which have been linked to the fraudulent scheme after forensic analysis.
The Force spokesman said further investigations identified Okitipi Samuel, also known as “RaccoonO365” and “Moses Felix,” as the principal suspect and developer of the phishing infrastructure.
He said the investigations reveal that he operated a Telegram channel through which phishing links were sold in exchange for cryptocurrency and hosted fraudulent login portals on Cloudflare using stolen or fraudulently obtained email credentials.
“Notably, investigations revealed no evidence linking the two other arrested individuals to the creation or operation of the phishing scheme.
CSP Hundeyin reaffirmed the Nigeria Police Force steadfast commitment to safeguarding Nigeria’s digital space through the deployment of advanced technology, strengthened international partnerships, and diligent investigative and prosecutorial processes aimed at effectively countering evolving cyber threats.









Got a Questions?
Find us on Socials or Contact us and we’ll get back to you as soon as possible.