Theregister
International Takedown of Kratos Phishing-as-a-Service Operation
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
On July 20, 2026, authorities from Germany, the USA, and Indonesia dismantled the Kratos phishing-as-a-service (PhaaS) operation, which had targeted hundreds of thousands of victims globally. The operation involved the arrest of the alleged developer in Indonesia and the neutralization of over 200 servers. Kratos facilitated the creation of convincing Microsoft-themed phishing pages, enabling low-skill cybercriminals to harvest credentials and bypass multi-factor authentication. Since its inception in 2024, the operation reportedly generated over €300,000 and involved around 1,800 criminal affiliates conducting approximately 15,000 phishing campaigns monthly. Victims spanned more than 30 countries, primarily in Europe and the USA. The takedown marks a significant achievement in combating a major online criminal service.
Key Points: • Kratos was a major phishing-as-a-service kit targeting Microsoft 365 users. • The operation involved the arrest of its developer in Indonesia and the shutdown of over 200 servers. • Authorities estimate hundreds of thousands of victims across more than 30 countries.