Skip to main content
The state of ai impact assessment
750 Million Fraudulent Accounts in 12 MonthsIdentity Lifecycle
5 min readFor IAM Architects

750 Million Fraudulent Accounts in 12 Months

The Challenge

In December 2023, Microsoft filed suit against Storm 1152, a Vietnamese cybercrime-as-a-service group responsible for creating and selling 750 million fraudulent Outlook and Hotmail accounts. These accounts were actively used for fraud, ransomware, and extortion.

The lawsuit temporarily disrupted Storm 1152's operations. However, by July 2024, Microsoft filed again as the group had reformed with new infrastructure.

This isn't an isolated incident. Okta Threat Intelligence found a Vietnamese ecosystem selling fraudulent accounts across platforms like Facebook, Instagram, LinkedIn, and TikTok. One marketplace offered Vietnamese Facebook accounts with 10-50 friends and Two-Factor Authentication enabled for 55,240 dong ($2.13 USD) each, with over 1,000 in stock.

The technical challenge: these registrations don't appear fraudulent during signup. They use disposable email services, complete verification flows, and may even enable 2FA. By the time your team identifies the pattern, thousands of accounts are already in your directory.

The Environment and Constraints

Service providers face a delicate balance. Reject too many signups and you lose legitimate customers. Accept too many fraudulent registrations and you risk:

  • SMS pumping attacks where automated signups trigger verification codes sent to premium-rate numbers
  • Phishing infrastructure appearing to originate from your platform
  • Interpersonal fraud scams using your accounts to build trust with victims
  • Artificial engagement inflation degrading trust in your platform's metrics

The Vietnamese ecosystem operates openly. Websites use templates from CMSNT.co, a web design company whose templates are widely adopted. These sites advertise "clone" Facebook accounts, "vintage" accounts from 2006, and accounts linked to disposable email services like mailclone[.]site and temp-mail[.]io.

The United Nations Office on Drugs and Crime's April 2025 report documented this surge of specialized service providers supporting fraud operations, particularly in Southeast Asia. The infrastructure is modular: you can buy accounts, phone farms, residential proxies, and anti-detect browsers.

Your IAM architecture must detect this activity without creating friction that drives legitimate users away. Apple's Hide My Email feature, for example, uses email masking for privacy. How do you distinguish that from mailclone[.]site?

The Approach Taken

Auth0 customers responding to fraudulent signup campaigns have several decision points before, during, and after account creation.

Pre-registration detection starts with Bot Detection capabilities that challenge automated registration attempts. This catches bulk signups driven by scripts, but sophisticated attackers will solve CAPTCHAs or use human solvers.

During registration, implement email domain reputation checks. The investigation revealed fraudulent registrations clustered around specific disposable email providers. Via17[.]com, one marketplace, recommends 11 disposable email services to buyers. Building a blocklist requires ongoing intelligence: when one service gets blocked, attackers rotate to another.

Session token analysis provides another signal. Some marketplaces sell not just credentials but session tokens (cookies) that allow buyers to access accounts without logging in. Monitoring for unusual session behavior, geographic inconsistencies, or rapid session token generation can flag compromised accounts.

Post-registration, behavioral analysis is critical. Legitimate users follow recognizable patterns: they complete profile setup, don't immediately connect with hundreds of strangers, and don't trigger SMS verifications to premium-rate numbers. Fraudulent accounts often deviate from these norms quickly.

The Storm 1152 case shows that disruption alone doesn't solve the problem. Microsoft's first legal action in December 2023 temporarily stopped operations. By July 2024, the group had rebuilt. Your detection and prevention measures must be continuous.

Results and Metrics

Microsoft's legal actions against Storm 1152 produced temporary disruption but not elimination. The group reformed within months.

For service providers implementing fraud detection, success metrics include:

  • Reduction in SMS pumping costs (measurable through telecom billing)
  • Decrease in customer complaints about spam or phishing from your platform
  • Lower rates of account takeover incidents

These metrics lag behind the attack. By the time you see increased SMS costs or customer complaints, thousands of fraudulent accounts may already exist in your directory.

What They Would Do Differently

The Vietnamese ecosystem's resilience suggests that purely defensive measures aren't enough. Storm 1152 reformed after legal disruption. The web storefronts using CMSNT.co templates continue operating openly.

A more effective approach would combine:

Intelligence sharing across service providers. If Facebook identifies a cluster of fraudulent registrations using mailclone[.]site addresses, that intelligence benefits LinkedIn, Instagram, and others under attack from the same infrastructure.

Proactive monitoring of cybercrime marketplaces. The storefronts Okta investigated operate on the clear web, not hidden darknet markets. You can monitor pricing, availability, and advertised features to understand what attackers are buying.

Friction that scales with risk. Rather than applying uniform verification requirements, implement progressive challenges. A signup from a known-good IP range with a corporate email domain gets minimal friction. A signup from a residential proxy using a disposable email address triggers additional verification steps.

Takeaways for Your Team

Don't treat disposable email services as a binary allow/block decision. Some users legitimately want privacy. Focus on behavioral patterns: does the account complete verification and then immediately trigger SMS codes to premium-rate numbers? Does it connect with hundreds of users within minutes of creation?

Build your detection logic to recognize infrastructure patterns, not just individual indicators. The Vietnamese ecosystem uses shared templates, shared email services, and shared proxy infrastructure. Identifying one fraudulent account should trigger review of others sharing those characteristics.

Accept that you're balancing false positives against fraud costs. Microsoft tolerated 750 million fraudulent accounts before taking legal action. That's not negligence; it's recognition that aggressive blocking would also reject legitimate users. Your threshold will depend on your business model, customer base, and fraud exposure.

Monitor the cybercrime-as-a-service market. When Via17[.]com advertises Facebook accounts with 2FA enabled, that's intelligence about attacker capabilities. When pricing drops, that suggests increased supply (successful attacks) or decreased demand (defenses are working).

Finally, recognize that legal disruption and technical defenses must work together. Microsoft's lawsuits bought time but didn't eliminate Storm 1152. Your IAM architecture must assume that disrupted groups will reform and that new groups will emerge to fill gaps in the market.

Application Security Isn’t Optional Anymore.

You Might Also Like