Police dismantle Kratos phishing platform, arrest developer

Global Phishing Platform Dismantled, Developer Arrested in Multi-Agency Operation

A major blow has been dealt to the world of cybercrime as authorities in Germany and the US have dismantled a vast phishing platform known as Kratos, shutting down its central infrastructure and arresting its developer. The operation, led by Frankfurt’s Prosecutor General Office (ZIT) and Germany’s Federal police (BKA), involved cooperation with US law enforcement agencies and was dubbed “Operation Olympus Blade”. With over 200 servers seized and the service rendered inoperable, it’s estimated that thousands of potential victims have been saved from phishing attacks.

Kratos was a platform-as-a-service (PhaaS) that offered its customers a simple way to conduct sophisticated phishing campaigns. Using convincing fake Microsoft authentication pages designed to steal email addresses and passwords, attackers could hijack Microsoft accounts and leverage them for further crimes such as business email compromise, data theft, account takeover, and phishing attacks targeting the victims’ contacts. With over 35 countries affected, particularly in Europe and the US, it’s clear that Kratos was a global operation with far-reaching consequences.

The platform allowed its users to create and manage fake login forms, effectively allowing them to impersonate legitimate Microsoft services. This toolkit was rented out to cybercriminals for a fee, generating significant revenue for the platform’s owner – estimated at over €300,000 since 2024. In addition to disrupting the malicious service, authorities believe that the seized servers will provide valuable forensic evidence in the ongoing investigation. As part of Operation Olympus Blade, domain ownership has been transferred to the FBI.

The dismantling of Kratos serves as a stark reminder of the need for individuals and organizations to prioritize cybersecurity measures. With the ever-evolving threat landscape, it’s crucial to stay one step ahead of attackers. This includes regularly updating security software, using strong passwords, and being cautious when receiving unsolicited emails or messages that ask for sensitive information.

In practical terms, this operation highlights the importance of conducting regular penetration testing and vulnerability assessments to identify weaknesses in your systems and networks before attackers do. By doing so, you can better protect yourself from phishing campaigns like Kratos and prevent potential security breaches.


Source: Bleeping Computer — 2026-07-21