In brief: German and US investigators have shut down the infrastructure of one of the world’s leading phishing kits specifically designed for MFA bypass in Microsoft 365.
German and US authorities have taken down the central infrastructure of the Kratos phishing kit, which according to the Frankfurt Public Prosecutor’s Office was among the most widely used criminal phishing tools globally. Indonesian authorities arrested the man they attribute with developing and operating the kit.
The Frankfurt Central Office for Cybercrime (ZIT) and the Federal Criminal Police Office (BKA) announced the dismantling on Monday. Kratos was specifically designed to steal Microsoft 365 sessions and bypass multi-factor authentication (MFA), and was widely used in phishing campaigns targeting corporate environments.
The phishing kit operated by hosting counterfeit Microsoft login pages that mimicked legitimate sign-in procedures. The infrastructure not only captured user credentials but also session tokens and MFA authentication factors, enabling direct access to Microsoft 365 accounts.
For CISOs, this case is significant because it demonstrates that even widely used and specialized phishing tools can be neutralized in a timely manner through coordinated international investigations. At the same time, it underscores the ongoing threat posed by professionally operated phishing infrastructures that are specifically designed to circumvent MFA security measures.
Source: thehackernews.com · Published 22 July 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.