Intentar ORO - Gratis
PHISHING EVOLVES INTO SCALABLE CYBERCRIME BUSINESS, SAYS RO'YA HATAMLEH
Security Advisor Middle East
|December 2025
RO'YA HATAMLEH OF MICROSOFT EXPLAINS HOW PHISHING-AS-A-SERVICE OPERATIONS LIKE RACCOONO365 ARE SCALING GLOBALLY, WHY CLOUD-FIRST REGIONS SUCH AS THE MIDDLE EAST FACE HEIGHTENED RISK, AND HOW ORGANISATIONS CAN COUNTER AI-DRIVEN ATTACKS THROUGH IDENTITY SECURITY AND ZERO TRUST.
-
Phishing has evolved from opportunistic scams into a highly industrialised cybercrime model, driven by automation, artificial intelligence, and subscription-based criminal services.
One of the most prominent examples is Raccoon0365, a phishing-as-a-service (PhaaS) operation that enabled large-scale credential theft across nearly 100 countries by lowering the technical barriers for cybercriminals.
Microsoft recently led a coordinated global takedown of Raccoon0365, seizing hundreds of domains and disrupting its infrastructure. The operation highlights both the growing sophistication of phishing campaigns and the importance of intelligence-led, collaborative defence in combating cybercrime at scale.
Ro'ya Hatamleh, Security Cloud Commercial Solutions, EMEA HQ – Middle East and Africa at Microsoft, spoke to Sandhya D'Mello, Technology Editor, CPI Media Group, about how the PhaaS model works, why cloud-first regions such as the Middle East face heightened risk, and how organisations can defend themselves against Al-driven phishing through strong identity security, Zero Trust principles, and continuous awareness.
Interview excerpts:
How does the phishing-as-a-service model like Raccoon0365 work, and why is it so powerful?
Raccoon0365 is a prime example of phishing-as-a-service (PhaaS), essentially a criminal subscription model. Even attackers with minimal technical skills can run large-scale phishing campaigns simply by paying a subscription fee. Once subscribed, they gain access to ready-made tools, templates, and email kits that mimic Microsoft 365 login pages, complete with convincing branding.
What makes it powerful are three key points:
- Scalability & Automation: Our investigation showed that Raccoon0365 could target up to 9,000 email addresses per day. Since July 2024, it was used to steal over 5,000 user credentials across 94 countries.
Esta historia es de la edición December 2025 de Security Advisor Middle East.
Suscríbete a Magzter GOLD para acceder a miles de historias premium seleccionadas y a más de 9000 revistas y periódicos.
¿Ya eres suscriptor? Iniciar sesión
MÁS HISTORIAS DE Security Advisor Middle East
Security Advisor Middle East
STARLINK SHARPENS AI-FIRST CYBERSECURITY VISION TO POWER KSA'S NEXT DECADE OF GROWTH
COO AHMED DIAB OUTLINES HOW DEEPER LOCAL INVESTMENT, AGENTIC AUTOMATION, AND VERTICAL-READY SOLUTIONS ARE POSITIONING STARLINK AT THE FOREFRONT OF THE KINGDOM'S CYBER RESILIENCE JOURNEY.
3 mins
December 2025
Security Advisor Middle East
AI AGENTS, MACHINE IDENTITIES TO RESHAPE BOARDROOM CYBERSECURITY PRIORITIES
KEVIN BOCEK, SENIOR VICE PRESIDENT OF INNOVATION AT CYBERARK, EXPLAINS WHY IDENTITY SECURITY WILL DEFINE GOVERNANCE, RESILIENCE AND DIGITAL TRUST IN 2026 AS AI AGENTS AND AUTOMATION RESHAPE CORPORATE DECISION-MAKING IN THE GULF AND BEYOND.
3 mins
December 2025
Security Advisor Middle East
GROUP-IB CHARTS NEXT FRONTIER OF CYBER DEFENCE IN SAUDI ARABIA
DMITRY VOLKOV HIGHLIGHTS HOW AI-DRIVEN THREATS, PREDICTIVE SECURITY, AND REAL-TIME FRAUD INTELLIGENCE SHARING ARE RESHAPING THE KINGDOM'S CYBERSECURITY ECOSYSTEM.
3 mins
December 2025
Security Advisor Middle East
VEEAM POSITIONS TRUSTED DATA AS FOUNDATION FOR SCALING SAFE AI, SAYS
CEO ANAND ESWARAN EXPLAINS HOW THE ACQUISITION OF SECURITI AI UNIFIES DATA RESILIENCE, SECURITY, GOVERNANCE, AND AI TRUST TO HELP ENTERPRISES MOVE AI FROM EXPERIMENTATION TO PRODUCTION WITH CONFIDENCE
3 mins
December 2025
Security Advisor Middle East
GITGUARDIAN ENTERS SAUDI ARABIA TO STRENGHTEN CYBERSECURITY FOR VISION 2030
GitGuardian, global leader in nonhuman identity cybersecurity, has officially entered the Saudi Arabian market by completing a 12-day strategic immersion under Business France's Booster Grow Global program.
3 mins
December 2025
Security Advisor Middle East
GOODBYE 2025, HELLO 2026! CYBER MATURITY MOVES FROM CONFIDENCE TO PROOF
CYBERSECURITY IN THE MIDDLE EAST IS SHIFTING FROM POINT CONTROLS TO ECOSYSTEM RESILIENCE. ATTACKERS ARE EXPLOITING THE SEAMS BETWEEN CLOUD PLATFORMS, AI-DRIVEN APPLICATIONS, PARTNERS, AND SUPPLIERS — WHILE BOARDS AND INSURERS DEMAND PROOF THAT CRITICAL DATA CAN BE RECOVERED CLEANLY, QUICKLY, AND WITHIN JURISDICTION. IN 2026, CYBER MATURITY WILL BE MEASURED, NOT ASSUMED.
12 mins
December 2025
Security Advisor Middle East
REDEFINING TRUST: WHY CREDENTIALS, NOT PASSWORDS, WILL SECURE ENTERPRISE
CRYPTOGRAPHIC, SYSTEM-GOVERNED CREDENTIALS ARE BECOMING THE ONLY SCALABLE FOUNDATION FOR ZERO TRUST SECURITY BEYOND PASSWORDS.
5 mins
December 2025
Security Advisor Middle East
HYBRID VISIBILITY, AI OBSERVABILITY, AND POST- QUANTUM READINESS WILL DEFINE 2026, SAYS GIGAMON OFFICIAL
DANIELLE KINSELLA, SENIOR DIRECTOR SALES ENGINEERING, GIGAMON, EXPLAINS HOW SAUDI ENTERPRISES ARE LEAPFROGGING GLOBAL MARKETS THROUGH GROUND-UP ARCHITECTURES, MULTICLOUD RESILIENCE AND TRAFFIC INTELLIGENCE.
2 mins
December 2025
Security Advisor Middle East
DATA-CENTRIC SECURITY TAKES CENTRE STAGE IN SAUDI ARABIA'S DIGITAL TRANSFORMATION
SECLORE'S URAZ FARUKH EXPLORES HOW THE KINGDOM'S REGULATORY DIRECTION AND AI ADOPTION ARE SHAPING THE FUTURE OF COMPLIANCE AND CYBER RESILIENCE.
2 mins
December 2025
Security Advisor Middle East
SANS INSTITUTE PARTNERS WITH UAE CYBERSECURITY COUNCIL TO ENHANCE NATIONAL CYBER CAPABILITIES AHEAD OF QUANTUM ERA
SANS Institute, the global leader in cybersecurity training and certifications, announced a landmark strategic partnership with the UAE Cybersecurity Council to advance the nation's cybersecurity readiness and reinforce the UAEs long-term vision for a secure and resilient digital future.
2 mins
December 2025
Listen
Translate
Change font size

