A major blow has been struck against global cybercrime operations with the dismantling of Kratos, a sophisticated phishing-as-a-service (PhaaS) platform. Authorities in Germany and the United States have taken down the central infrastructure of the platform, seizing over 200 servers and rendering it inoperable. The developer behind the platform was also arrested in Indonesia.
Kratos had been one of the world’s most widely used criminal phishing services, with confirmed victims across 35 countries, particularly in Europe and the United States. According to German authorities, more than 1,800 cybercriminals had purchased access to the platform, using it to conduct around 15,000 phishing campaigns per month. Each campaign had the potential to affect thousands of recipients worldwide.
The Kratos platform allowed threat actors to create and manage fake Microsoft authentication pages, designed to steal email addresses and passwords. This enabled them to hijack Microsoft accounts, which were often used as a springboard for further crimes such as business email compromise, data theft, account takeover, and phishing attacks targeting the victims’ contacts.
The PhaaS model is particularly insidious because it makes it easy for cybercriminals to access sophisticated tools without needing extensive technical expertise. By renting out these tools, the developers of Kratos were able to rake in significant profits – at least €300,000 since 2024 from subscription fees alone. With the shutdown of the platform and the arrest of its developer, authorities believe that these phishing campaigns can no longer continue.
The takedown of Kratos is a significant victory for law enforcement agencies, but it’s also a reminder of the ongoing threat posed by PhaaS platforms. As long as these services are available, cybercriminals will continue to use them to carry out large-scale attacks. It’s essential for organizations and individuals alike to remain vigilant and take steps to protect themselves against phishing attacks.
The shutdown of Kratos is a timely reminder that no one is immune to the threat of phishing. With phishing kits like this becoming increasingly sophisticated, it’s crucial to stay ahead of the game by regularly testing your security controls and staying up-to-date with the latest threats. Don’t wait for attackers to test your defenses – test every layer of your security stack yourself to ensure you’re prepared for whatever comes next.
Source: Bleeping Computer — 2026-07-21