osthessen-news.de Global Phishing Service Kratos Taken Down by Law Enforcement
Article Content
- •Kratos phishing service infrastructure dismantled, impacting hundreds of thousands of victims.
- •Over 200 servers taken offline, halting 15,000 monthly phishing campaigns.
- •Developer arrested in Indonesia; operation marks a significant law enforcement success.
A joint operation by the German Federal Criminal Police (BKA) and U.S. authorities has dismantled the infrastructure of Kratos, a major phishing service responsible for stealing credentials from hundreds of thousands of victims across over 30 countries. The service allowed criminals to create convincing fake Microsoft authentication pages to harvest sensitive information. The developer and technical administrator of Kratos was arrested in Indonesia, and over 200 servers were shut down, effectively halting ongoing phishing campaigns. The operation is considered a significant success in combating phishing-as-a-service models, which had generated over 300,000 euros since 2024. More than 1,800 criminals had utilized Kratos to run approximately 15,000 phishing campaigns monthly, targeting thousands of potential victims worldwide. The BKA emphasized that this action sends a strong message to cybercriminals that such activities will not go unpunished.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track Microsoft in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…