German-led operation dismantles Kratos phishing kit infrastructure and arrests alleged developer in Indonesia

German and Indonesian authorities say they dismantled the Kratos phishing-as-a-service platform, which was used to steal Microsoft account logins and session cookies from victims in more than 30 countries. Prosecutors and the BKA said the operation neutralized more than 200 servers and led to the arrest in Indonesia of the alleged developer and technical administrator. Authorities estimate more than 1,800 criminal customers used Kratos for roughly 15,000 phishing campaigns a month since 2024.
Why it matters: Kratos helped low-skill criminals run convincing Microsoft-themed phishing campaigns at scale, including attacks that could bypass multi-factor authentication by stealing session cookies. Organizations should review Microsoft 365 phishing defenses, hunt for token and session theft, and warn users about fake login pages and document lures.

Sources

In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws
SecurityWeek News 2026.07.24 84% relevant
This roundup reports the same German law-enforcement takedown of the Kratos phishing group, adding concise confirmation that the operation disrupted an organized credential-theft and phishing ring.
Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA
info@thehackernews.com (The Hacker News) 2026.07.22 99% relevant
This article appears to cover the same law-enforcement takedown of the Kratos phishing-as-a-service platform, adding reporting detail that the kit was built to steal Microsoft 365 session cookies and defeat MFA protections.
Police dismantle Kratos phishing platform, arrest developer
Bill Toulas 2026.07.21 99% relevant
This is the same underlying event: German and U.S. authorities seized more than 200 servers tied to the Kratos phishing platform and arrested its developer in Indonesia, adding scale details such as 1,800 customers, about 15,000 phishing campaigns per month, victims in 35 countries, and Kratos’s focus on fake Microsoft login pages.
Kratos phishing-as-a-service kit loses its battle with international law enforcement
2026.07.21 100% relevant
This article establishes a distinct tracked event: the international takedown of the Kratos/SneakyLog phishing platform and arrest of its alleged operator, rather than a patch, breach disclosure, or previously tracked phishing-kit story.
← Back to all stories