• 2 min read
Kratos phishing platform dismantled, developer arrested
Authorities seized more than 200 Kratos servers and arrested its developer, disrupting a phishing service used in 35 countries.

Image: BleepingComputer
Authorities in Germany and the United States have dismantled the central infrastructure of Kratos, a phishing-as-a-service platform used worldwide. The operation seized more than 200 servers, rendering the service inoperable, while Indonesian authorities arrested its developer.
The action was led by Frankfurt’s Prosecutor General Office (ZIT) and Germany’s Federal Criminal Police Office (BKA), in cooperation with U.S. law enforcement agencies.
Kratos phishing service targeted Microsoft accounts
The BKA described Kratos as “one of the world’s most widely used criminal phishing services.” Authorities confirmed victims in 35 countries, particularly across Europe and the United States.

Recommended reading
OpenAI models escaped a sandbox and breached Hugging Face
“Authorities believe that more than 1,800 criminal customers purchased Kratos and used it to conduct roughly 15,000 phishing campaigns per month. Each campaign had the potential to affect several thousand recipients worldwide.”
Kratos was rented to cybercriminals who used it to create and manage fake Microsoft authentication pages. Its phishing kits included convincing login forms designed to steal email addresses and passwords, allowing attackers to hijack Microsoft accounts.
The compromised accounts were then used to commit further crimes, including business email compromise, data theft, account takeover, and attacks against the victims' contacts, according to the BKA.
Kratos infrastructure seized in Operation Olympus Blade
Authorities estimate that the service’s owner earned at least €300,000 ($342,000) from subscription fees since 2024. The arrest of its technical administrator and the seizure of key infrastructure have stopped the platform’s phishing campaigns, the BKA said.
Seizure banner — Source: BKA
A seizure banner on Kratos' website says the action was part of Operation Olympus Blade and that domain ownership has been transferred to the FBI. Investigators can now examine the seized servers for forensic evidence that could help identify the platform’s customers.
Security Editor
Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.
via BleepingComputer


