Theregister
Global Takedown of Kratos Phishing-as-a-Service Infrastructure
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
On July 20, 2026, German and U.S. authorities dismantled the Kratos phishing-as-a-service (PhaaS) platform, arresting its developer in Indonesia. The operation neutralized over 200 servers and disrupted approximately 15,000 phishing campaigns monthly, affecting hundreds of thousands of victims across more than 30 countries, primarily in Europe and the U.S. Kratos allowed low-skill cybercriminals to create convincing Microsoft-themed phishing pages, facilitating credential theft and further crimes. The platform generated over €300,000 since 2024, with around 1,800 criminal affiliates utilizing the service. The takedown marks a significant achievement in combating sophisticated phishing infrastructures.
Key Points: • Kratos was a major phishing-as-a-service platform targeting Microsoft 365 users. • Over 200 servers were seized, disrupting 15,000 phishing campaigns per month. • The operation involved collaboration between German, U.S., and Indonesian law enforcement.