Bottom Line: German and US authorities have shut down the phishing service Kratos, which enabled over 1,800 criminal users to conduct approximately 15,000 campaigns per month, and arrested its operator in Indonesia.
The German Federal Criminal Police Office and the Central Office for Combating Internet Crime have jointly with US investigators deactivated the core infrastructure of the phishing service Kratos. The service was one of the most widely distributed phishing kits worldwide.
The German Federal Criminal Police Office (BKA) and the Central Office for Combating Internet Crime (ZIT) at the General Public Prosecutor’s Office Frankfurt, together with US authorities, have deactivated the infrastructure of the phishing service Kratos. The developer and technical administrator was arrested in Indonesia. According to investigators, core technical components have been shut down and the entire Kratos infrastructure has been taken offline. More than 200 servers operated by the group were neutralized.
Kratos was a digital kit that enabled cybercriminals to create and manage deceptively authentic Microsoft authentication web pages. These pages were used to steal access credentials such as passwords and email addresses. The business model was based on renting the kit to other cybercriminals who then independently conducted phishing campaigns. This made it possible for technically less sophisticated actors to carry out large-scale attacks. Since 2024, the group is said to have generated over 300,000 euros in revenue.
According to authorities, more than 1,800 criminal “franchisees” acquired Kratos and used it to conduct approximately 15,000 phishing campaigns per month. Each campaign had the potential to harm several thousand recipients worldwide. The number of victims comes from more than 30 countries, predominantly from Europe and the US, and has amounted to hundreds of thousands since the end of 2024. The operation also prevented attacks targeting hundreds of thousands of potential victims worldwide.
For CISOs, this success is relevant because Kratos-based attacks could operate with high professionalization and reach. The dismantling of the infrastructure directly reduces the threat surface, while the broad availability of the kit demonstrates that technically based attacks can be stopped through coordinated international investigations. Carsten Meywirth, head of the Cybercrime division at the BKA, emphasizes that the operation shows that even highly professional phishing infrastructure can be effectively combated.
Source: www.it-daily.net · Published 20 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.7.3.