Global Police Dismantle Kratos Phishing-as-a-Service Platform, Arrest Developer
German and US authorities have dismantled the Kratos phishing-as-a-service platform, arresting its developer in Indonesia and seizing over 200 servers.

Global law enforcement agencies, led by German and U.S. authorities, have successfully dismantled the Kratos phishing-as-a-service (PhaaS) platform, a significant blow to cybercriminals who relied on its infrastructure for widespread phishing campaigns. The operation culminated in the arrest of the platform's developer in Indonesia and the seizure of over 200 servers, effectively rendering the malicious service inoperable.
The joint effort, spearheaded by Frankfurt’s Prosecutor General Office (ZIT) and Germany’s Federal police (BKA) in collaboration with U.S. law enforcement, targeted the core servers and backend systems of Kratos. The BKA described Kratos as "one of the world’s most widely used criminal phishing services," with a reach extending to victims in 35 countries, particularly across Europe and the United States. Authorities estimate that more than 1,800 criminal customers rented the platform, conducting approximately 15,000 phishing campaigns monthly, each with the potential to impact thousands of recipients worldwide.
The Kratos toolkit was designed to facilitate the creation and management of highly convincing fake Microsoft authentication pages. Threat actors utilized these pages to harvest email addresses and passwords, enabling them to hijack Microsoft accounts. The compromised accounts were then frequently leveraged for further criminal activities, including business email compromise (BEC), data theft, and additional phishing attacks targeting the victims' contacts.
Investigators estimate that the owner of the Kratos platform amassed at least €300,000 (approximately $342,000 USD) in revenue since 2024 through subscription fees. The arrest of the technical administrator and the disruption of the platform's infrastructure mean these specific phishing campaigns can no longer continue.
A seizure banner has been displayed on the service's former website, marking the operation as "Operation Olympus Blade." The banner also indicates that domain ownership has been transferred to the FBI. The seized servers are expected to provide crucial forensic evidence, aiding investigators in identifying and pursuing the platform's customers.
The dismantling of Kratos represents a significant victory in the ongoing fight against phishing-as-a-service operations, which lower the barrier to entry for cybercrime by providing ready-made tools and infrastructure. By removing such platforms, law enforcement aims to disrupt the cybercriminal ecosystem and prevent widespread credential theft and subsequent fraud.
This operation underscores the importance of international cooperation in combating sophisticated cybercrime. The successful takedown of Kratos demonstrates the capability of law enforcement agencies to track down and apprehend individuals behind global cybercriminal enterprises, even when operating across multiple jurisdictions.
The Kratos operation, which provided a toolkit for creating fake Microsoft login pages, impacted an estimated 1,800 criminal customers and generated over €300,000 since 2024. Indonesian authorities arrested the alleged developer and technical administrator of the Kratos infrastructure, and investigators neutralized more than 200 servers connected to the service.
The Kratos phishing kit, also known as SneakyLog by Microsoft Threat Intelligence, was designed to steal both credentials and session cookies, enabling adversary-in-the-middle attacks that bypass multi-factor authentication. Investigators estimate that approximately 1,800 paying customers used Kratos to conduct around 15,000 phishing campaigns monthly, impacting hundreds of thousands of victims across over 30 countries since late 2024.
The article provides further details on the Kratos phishing-as-a-service (PhaaS) platform's operational scale, estimating that over 1,800 "criminal franchisees" utilized the service to launch approximately 15,000 phishing campaigns monthly. It also reveals that the alleged administrator earned at least €300,000 in subscription fees since 2024, with payments accepted via cryptocurrency.
The Kratos phishing-as-a-service platform, which was dismantled by global authorities, has seen its reusable toolkit and methods continue to pose a significant threat. Despite the disruption, the platform's sophisticated AiTM techniques, which capture passwords and active session tokens to bypass MFA, are now serving as a blueprint for other threat actors. This evolution means that even though Kratos itself may be less active, its underlying methodologies are being adopted and adapted by others to attack Microsoft 365 users.