Updated
Updated · The Hacker News · Jul 22
German, US Authorities Dismantle 200-Server Kratos Phishing Network, Arresting Developer
Updated
Updated · The Hacker News · Jul 22

German, US Authorities Dismantle 200-Server Kratos Phishing Network, Arresting Developer

3 articles · Updated · The Hacker News · Jul 22

Summary

  • More than 200 Kratos servers were taken offline and Indonesian authorities arrested the alleged developer, disrupting a phishing-as-a-service platform tied to hundreds of thousands of victims in over 30 countries since late 2024.
  • Investigators said roughly 1,800 customers used Kratos for about 15,000 campaigns a month, stealing Microsoft 365 credentials and session cookies that let attackers bypass two-factor authentication.
  • Microsoft tracked the kit as SneakyLog and linked it to campaigns since at least early 2025, including a Feb. 10 tax-themed QR-code lure sent to about 100 mostly US organizations.
  • Microsoft is notifying affected users because password resets alone do not stop Kratos's reverse-proxy mode; stolen live sessions must be revoked and high-value accounts shifted to phishing-resistant sign-in.
  • The takedown halted current Kratos-powered campaigns, but investigators said the code and its roughly 1,800 customers remain at large, leaving room for the service to reappear under a new name.

Insights

With Kratos's code in the hands of 1,800 criminals, when and where will the next wave of attacks surface?
Is the global shift to passwordless logins the final answer to phishing, or just the start of a new security arms race?
Does this takedown signal a real crackdown on Indonesia's cybercrime hubs, or is it merely a symbolic victory for law enforcement?

Global Takedown of Kratos: 15,000 Phishing Campaigns Disrupted, 1,800 Criminal Customers Exposed

Overview

On July 22, 2026, a major global law enforcement operation led by German authorities dismantled the Kratos phishing platform, one of the most dangerous Phishing-as-a-Service kits. By taking Kratos’s servers offline, officials completely halted its ability to launch new phishing attacks, immediately disrupting its estimated 15,000 monthly campaigns. This takedown marks a significant blow to cybercriminals worldwide, as Kratos had enabled widespread credential theft and supported a large network of criminal customers. The operation highlights the power of international cooperation in combating advanced cybercrime and sets a strong precedent for future efforts.

...