Microsoft won a court-authorized seizure of rockcaptcha.com on July 23, 2024, alleging that it was a replacement storefront for Storm-1152, a Vietnam-based cybercrime-as-a-service operation. The group allegedly sold fraudulent Microsoft accounts and CAPTCHA-bypass services that helped other criminals scale phishing, spam, ransomware, data theft, extortion and fraud.
The action was a civil domain seizure in the U.S. District Court for the Southern District of New York—not a criminal conviction or an arrest. It followed Microsoft’s December 2023 disruption of earlier Storm-1152 infrastructure.
What Microsoft seized
The target was the domain rockcaptcha.com, also referenced in court material as rockcaptcha[.]com. A federal judge in the Southern District of New York approved the seizure on July 23, 2024. CyberScoop reported the action after court documents were unsealed on July 31.
In this context, “seized” means Microsoft obtained legal authority through a civil case to take control of, redirect or otherwise disable the domain and associated online presence. It does not mean that Microsoft physically confiscated every server, located every customer, or arrested the alleged operators.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →#1 Best Overall
Microsoft described the July action as a follow-up against a replacement operation. The domain was only one identified part of a wider ecosystem that could include backend hosting, messaging channels, payment accounts, stolen-account inventories and copycat sites.
CyberScoop’s report on the seizure and Microsoft’s July 2024 account describe the court action and its alleged connection to Storm-1152.
Who Storm-1152 allegedly was
Storm-1152 is Microsoft’s designation for a Vietnam-based cybercrime-as-a-service operation. Microsoft said it operated like an online software business, with public websites, social-media marketing, instructional videos, customer support and payment systems.
The alleged products included fraudulent Outlook and Hotmail accounts, CAPTCHA-solving services and tools intended to defeat identity-verification checks on technology platforms. Microsoft identified Duong Dinh Tu, Linh Van Nguyễn (also identified as Nguyễn Van Linh), and Tai Van Nguyen as alleged leaders or operators.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteThose are allegations in Microsoft’s civil case and threat-intelligence reporting. The available coverage does not establish that the named people were convicted or arrested, so they should not be described as adjudicated criminals.
Microsoft’s original complaint is available as a court-document PDF.
How large was the alleged account business?
Microsoft said Storm-1152 had created approximately 750 million fraudulent Microsoft accounts for sale. Before the first disruption, Microsoft reportedly estimated that the operation was generating about one million new accounts per week. After the December 2023 action, Microsoft said the group generated about one million accounts in total, indicating a much smaller operating rate.
The 750-million figure is Microsoft’s estimate or investigative claim, not an independently audited count of unique, active accounts. It may include accounts later disabled, duplicated, inactive or never purchased. It should not be presented as 750 million active users or victims.
Free tools Windows power users keep installed
One-click scans. No signup required.
Microsoft also reported an approximately 60% drop in sign-up traffic after its first disruption, attributing much of the reduction to abusive sign-ups that Microsoft or its partners later identified and suspended. That measurement describes traffic and abuse patterns, not a permanent disappearance of the market.
Why criminals buy fake accounts
Fraudulent accounts are infrastructure for other attacks, not merely counterfeit consumer products. A supply of identities lets customers launch campaigns without building reputations or passing normal account-creation controls themselves.
Rank #3
- Phishing and spam: Disposable senders can distribute more malicious messages and replace accounts that are blocked.
- Social engineering: A seemingly ordinary Microsoft identity can make a message or support interaction appear more credible.
- Abuse of cloud and platform features: Accounts can be used to obtain trials, services or quotas and to evade per-user limits.
- Reputation evasion: Large pools of identities make it harder for platforms to distinguish new abuse from legitimate sign-ups.
- Ransomware, theft and extortion support: Accounts can provide access points, communication channels or staging resources for campaigns run by other groups.
Microsoft linked accounts supplied by Storm-1152 to financially motivated actors including Octo Tempest, also known as Scattered Spider, and groups it tracks as Storm-0252 and Storm-0455. That attribution does not mean Storm-1152 itself carried out every downstream attack; its alleged role was primarily that of an enabling supplier.
See Microsoft’s December 2023 announcement for its account of the supply chain and linked threat groups.
Recommended Free Tools
What CAPTCHA bypass services changed
CAPTCHAs and related identity checks are intended to separate human users from automated or abusive account creation. Microsoft said Storm-1152 sold tokens, tools or services that helped customers get past those controls.
Microsoft’s later account said the operation initially offered bypass services and later adapted by using bot-harvested, CAPTCHA-defeating tokens to create accounts for resale. Microsoft and cybersecurity company Arkose Labs described automation and AI- or machine-learning-assisted solving at scale.
The evidence supports describing the process as automated or AI-assisted. It does not establish a particular generative-AI model, architecture, training data or a fully autonomous system.
Rank #4
The December 2023 disruption
On December 7, 2023, Microsoft obtained a Southern District of New York order to seize U.S.-based infrastructure and take Storm-1152 websites offline. The properties Microsoft identified included:
- hotmailbox.me, which allegedly sold fraudulent Outlook accounts;
- 1stCAPTCHA;
- AnyCAPTCHA;
- NoneCAPTCHA; and
- social-media pages used to advertise the services.
Microsoft said Arkose Labs provided intelligence support. Microsoft publicly announced the operation on December 13, 2023.
How the operation rebuilt
According to Microsoft filings described by CyberScoop, a Vietnamese-language post dated January 29, 2024, advertised a new RockCAPTCHA site. Microsoft investigators said the people connected to that post were the same individuals associated with the earlier operation.
The rebuilt service reportedly operated on a smaller scale. Microsoft nevertheless argued that a second seizure could damage the group’s ability to attract customers, restore trust and expand infrastructure. The July 23 action was therefore an iterative disruption, not an unrelated first takedown.
Timeline
| Date | Event |
|---|---|
| At least 2021 | The complaint alleges the account and CAPTCHA-bypass scheme was already operating. |
| 2022 | Microsoft said it was tracking the growth of fraudulent-account activity. |
| February 2023 | Microsoft threat intelligence began formalizing the activity as Storm-1152. |
| March 2023 | A Microsoft customer experienced a major spam-related disruption involving large numbers of fraudulent Outlook and Hotmail accounts. |
| December 7, 2023 | Microsoft obtained the order for its first infrastructure seizure. |
| December 13, 2023 | Microsoft announced the disruption and its estimate of about 750 million accounts created for sale. |
| January 29, 2024 | A post advertised the replacement RockCAPTCHA operation, according to Microsoft’s filings. |
| July 23, 2024 | A federal judge approved seizure of rockcaptcha.com. |
| July 31, 2024 | CyberScoop reported the seizure after documents were unsealed. |
| August 7, 2024 | Microsoft published a detailed account of the investigation and second legal action. |
What the seizure achieved—and what it did not
Likely benefits
- Interrupted an identified storefront and its customer-acquisition channel.
- Raised the cost of rebuilding a recognizable brand and support operation.
- Helped Microsoft and partners identify and suspend abusive sign-ups.
- Provided intelligence about customers, infrastructure and techniques used to evade controls.
Limits
- A domain seizure does not automatically disable every account previously sold.
- Backend servers, encrypted messaging channels, payment methods and inventories may remain.
- Operators can change domains, hosting providers, branding and delivery methods.
- Copycat suppliers can replace a disrupted service.
- A civil seizure does not itself establish criminal guilt.
The sequence from December disruption to RockCAPTCHA illustrates why cybercrime takedowns are usually iterative. Microsoft disrupted and degraded an operation; it did not prove that the broader market for fraudulent accounts had vanished.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Best Value
What ordinary Microsoft users should do
The action targeted a supply chain supporting abuse, not individual account holders. A seized domain does not by itself mean that every account associated with it has been disabled or that phishing and ransomware threats have ended.
- Enable multifactor authentication and use passkeys where Microsoft supports them.
- Use unique passwords and never reuse a Microsoft password on another service.
- Treat unexpected security notices, file-share invitations and payment requests as potential phishing.
- Review recent sign-ins, forwarding rules, recovery methods and third-party app permissions.
- Report suspicious messages through your organization’s established reporting channel.
What organizations should learn
Storm-1152 shows how an account factory can lower the cost of attacks for many unrelated criminal groups. Defenses therefore need to address both account creation and activity after registration.
- Harden sign-up: Combine rate limits, device and network reputation, risk-based verification and resilient CAPTCHA controls rather than relying on one challenge.
- Watch for anomalies: Investigate bursts of new accounts, shared device fingerprints, unusual geographic patterns and rapid movement from registration to high-volume messaging.
- Protect cloud resources: Monitor trial usage, OAuth grants, mailbox creation, outbound email volume and access to sensitive data.
- Build account reputation over time: Apply stricter limits to new or untrusted identities and require stronger proof for risky actions.
- Share intelligence: Coordinate domain, payment, hosting and indicator information with providers, partners and relevant authorities.
The broader cybercrime lesson
This case is an example of the industrialization of cybercrime. Attackers can purchase accounts, CAPTCHA solving, hosting, phishing kits, malware and technical support instead of developing every capability themselves. Public websites, tutorials, support desks and payment systems can make those services resemble legitimate software businesses.
Disrupting an enabling supplier can affect several downstream campaigns at once. But the resilience lesson is equally important: infrastructure seizures work best alongside account suspension, abuse detection, intelligence sharing and criminal investigations.
Microsoft’s Digital Crimes Unit explains its broader disruption model on its Digital Crimes Unit page.
Frequently Asked Questions
Was Storm-1152 convicted in the Microsoft case?
The available reporting describes a civil, court-authorized domain seizure and Microsoft’s allegations. It does not establish a criminal conviction or arrest of the named individuals.
Did Microsoft seize all 750 million accounts?
No. The 750-million figure was Microsoft’s estimate of fraudulent accounts created for sale. The July action targeted the identified RockCAPTCHA domain and related infrastructure, not every account or customer in the ecosystem.
Does a domain seizure stop phishing and ransomware?
It can interrupt a supplier and raise rebuilding costs, but it does not eliminate downstream campaigns, previously sold accounts or replacement providers.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




