Authorities Shut Down Kratos Phishing Platform Behind 15,000 Monthly Campaigns
German, US, and Indonesian authorities have dismantled Kratos, a phishing-as-a-service platform linked to around 15,000 phishing campaigns every month.
Investigators disabled the platform’s central infrastructure, neutralized more than 200 servers, and supported the arrest of its alleged developer and technical administrator in Indonesia.
Access content across the globe at the highest speed rate.
70% of our readers choose Private Internet Access
70% of our readers choose ExpressVPN
Browse the web from multiple devices with industry-standard security protocols.
Faster dedicated servers for specific actions (currently at summer discounts)
The German Federal Criminal Police Office, known as the BKA, said Kratos had affected hundreds of thousands of victims across more than 30 countries. Most identified victims were located in Europe and the United States.
Kratos Phishing Infrastructure Taken Offline
The international operation targeted the systems that allowed Kratos customers to create, host, and manage phishing campaigns. Taking down the central infrastructure disrupted active campaigns and prevented customers from continuing to use the platform.
The operation involved Germany’s BKA and the Central Office for Combating Internet Crime at the Frankfurt General Prosecutor’s Office. US authorities and Indonesian law enforcement also supported the investigation.
According to reporting on the Kratos takedown, Indonesian authorities arrested the suspected developer while investigators moved against servers supporting the service.
| Kratos operation detail | Reported figure |
|---|---|
| Servers neutralized | More than 200 |
| Criminal customers | More than 1,800 |
| Monthly phishing campaigns | Approximately 15,000 |
| Revenue generated since 2024 | More than €300,000 |
| Victim reach | Hundreds of thousands across more than 30 countries |
What Was the Kratos Phishing Platform?
Kratos operated as a phishing-as-a-service platform, often shortened to PhaaS. The service gave paying customers a ready-made system for building and managing fraudulent login pages.
Authorities described it as a digital construction kit for cybercrime. Customers did not need to develop their own phishing websites, hosting systems, or credential collection tools.
Kratos focused heavily on pages designed to imitate Microsoft authentication services. These fake websites attempted to convince victims that they were signing into a legitimate Microsoft account or Microsoft 365 service.
- Customers could create convincing Microsoft login pages.
- The platform hosted or managed the supporting phishing infrastructure.
- Captured usernames and passwords were sent to the attacker.
- Subscribers could run multiple campaigns without advanced technical skills.
- Each campaign could potentially reach thousands of recipients.
More Than 1,800 Criminal Customers Used Kratos
Investigators estimate that more than 1,800 customers purchased access to the platform. These users reportedly launched around 15,000 phishing campaigns every month.
The figures show how service-based cybercrime can increase the scale of online fraud. One development team can provide tools to thousands of separate attackers operating in different countries.
The BKA announcement said the Kratos group generated more than €300,000 from its criminal service since 2024. Authorities compared its subscribers to franchisees because they rented the central platform while running their own campaigns.
Fake Microsoft Login Pages Stole Account Credentials
Kratos customers used fraudulent login forms to collect email addresses, passwords, and other personal information. The pages closely copied familiar Microsoft authentication screens to reduce suspicion.
A victim could receive a message claiming that a shared document, security alert, password reset, invoice, or Microsoft 365 file required immediate attention. The included link would then open a Kratos-generated phishing page.
Once a victim entered account details, the information became available to the attacker. Those credentials could provide access to email, cloud storage, corporate applications, or other services connected to the same account.
| Stolen access | Possible criminal use |
|---|---|
| Microsoft 365 email | Business email compromise, internal phishing, and payment fraud |
| OneDrive or SharePoint | Theft of documents, customer records, and business information |
| Corporate identity account | Access to connected cloud applications and internal services |
| Reused password | Credential-stuffing attacks against other accounts |
| Trusted employee mailbox | Phishing messages sent to colleagues, customers, and suppliers |
Why Phishing-as-a-Service Creates a Larger Threat
Traditional phishing operations required attackers to develop websites, register domains, configure servers, and build systems for collecting stolen data.
Phishing-as-a-service platforms package much of that work into a single product. Customers can concentrate on selecting targets and distributing malicious links.
This model allows less experienced criminals to launch professional-looking attacks. It also lets experienced groups run more campaigns without repeatedly building new infrastructure.
- Ready-made templates reduce development work.
- Central dashboards simplify campaign management.
- Shared infrastructure supports attacks in multiple countries.
- Subscription revenue funds updates and technical support.
- Criminal customers can quickly replace blocked phishing pages.
Takedown Targeted the Core of the Kratos Service
Authorities did not limit their action to individual phishing pages or domains. They targeted the central systems that supported the wider Kratos network.
More than 200 servers were neutralized, while the suspected technical administrator was arrested in Indonesia. The coordinated action removed the infrastructure that customers needed to create and manage campaigns.
The international enforcement operation therefore caused broader disruption than removing isolated phishing websites. However, former Kratos customers may attempt to migrate to competing services or build replacement infrastructure.
Organizations Still Face Microsoft Account Phishing
The removal of Kratos does not eliminate phishing attacks against Microsoft users. Other criminal platforms can provide similar templates, hosting services, and account-stealing features.
Organizations should treat unexpected Microsoft login prompts, shared-document notices, password warnings, and account verification messages as high-risk themes.
Employees should open Microsoft services through trusted bookmarks or known application links instead of signing in through unsolicited messages. Security teams should also investigate newly registered domains that imitate company names or Microsoft services.
Phishing-Resistant Authentication Can Limit Credential Theft
Standard multifactor authentication offers stronger security than passwords alone, but some methods remain vulnerable to social engineering and real-time phishing techniques.
Microsoft recommends deploying phishing-resistant multifactor authentication, including passkeys, FIDO2 security keys, and Windows Hello for Business.
These methods use public-key cryptography and bind the authentication process to the legitimate service. A fake website cannot simply reuse a stolen passkey in the way an attacker might reuse a captured password.
- Require passkeys or FIDO2 security keys for administrators and high-risk users.
- Disable unused legacy authentication methods.
- Monitor sign-ins from unfamiliar locations, devices, and network addresses.
- Block newly registered and lookalike domains where appropriate.
- Rotate credentials immediately after suspected phishing exposure.
- Revoke active sessions when an account may have been compromised.
- Train employees to inspect the domain before entering login details.
Kratos Takedown Disrupts an Industrial Phishing Network
The Kratos operation shows how phishing has developed into a service industry. Platform operators build and maintain the infrastructure, while customers pay to run campaigns against their chosen targets.
Disabling the servers and arresting the suspected administrator removed a major provider from that market. It also prevented ongoing Kratos campaigns from continuing through the same infrastructure.
Organizations should use the disruption as an opportunity to review identity protections. Microsoft’s guidance for phishing-resistant MFA recommends replacing authentication methods that attackers can intercept or reuse with stronger passkey and FIDO2-based options.
FAQ
Kratos was a phishing-as-a-service platform that allowed criminal customers to create and manage fake login pages, particularly websites designed to imitate Microsoft authentication portals.
German authorities estimate that more than 1,800 criminal customers used Kratos to launch approximately 15,000 phishing campaigns every month.
Authorities neutralized more than 200 servers connected to the platform and disabled its central technical infrastructure.
The German Federal Criminal Police Office said Kratos affected hundreds of thousands of victims across more than 30 countries, mainly in Europe and the United States.
Indonesian authorities arrested the suspected developer and technical administrator of the Kratos platform as part of the coordinated international operation.
Organizations should deploy passkeys or FIDO2 security keys, monitor suspicious sign-ins, block lookalike domains, revoke compromised sessions, and train users to verify login addresses before entering credentials.
Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more
User forum
0 messages