← All stories
● Covered by 1 source · 1 reportHigh impact

Authorities dismantle Kratos phishing platform; developer arrested in Indonesia

German and U.S. authorities shut down the Kratos phishing-as-a-service platform, arresting its developer in Indonesia. This disruption is significant due to Kratos' extensive use, with customers allegedly conducting around 15,000 phishing campaigns monthly across 35 countries.

Key points

  • Kratos is linked to 15,000 phishing campaigns monthly.
  • Over 200 servers seized, disrupting operations.
  • Developer arrested; domain ownership transferred to FBI.

Operation Details

Authorities in Germany and the U.S. have dismantled Kratos, a significant phishing-as-a-service platform, in a coordinated operation. The effort led by Frankfurt's Prosecutor General Office and Germany's Federal Police resulted in the seizure of more than 200 servers, effectively rendering the service inoperable and arresting its developer in Indonesia.

Phishing Activity and Impact

Kratos has been described as one of the most widely utilized criminal phishing services globally, with more than 1,800 criminal customers confirmed. The platform facilitated roughly 15,000 phishing campaigns each month, primarily targeting users in Europe and the U.S., which could potentially affect thousands of victims.

Technical Capabilities of Kratos

The toolkit provided by Kratos allowed threat actors to create and manage convincing fake Microsoft authentication pages, enabling them to steal login credentials. Once attackers gained access to victims' Microsoft accounts, they often engaged in further criminal activity, including data theft and business email compromises.

Financial Gains and Future Investigations

The owner of the Kratos service reportedly generated at least €300,000 (approximately $342,000) from subscriptions since 2024. With the seizure of critical infrastructure, authorities anticipate recovering more forensic evidence that may lead to identifying more customers and their activities associated with the service.

Conclusion

The operation against Kratos signifies a major step in combating phishing as a service globally. By disrupting such platforms, law enforcement aims to reduce the number of successful phishing attacks and protect potential victims.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~39 min · 34 stories · Jul 21

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

German and U.S. authorities shut down the Kratos phishing-as-a-service platform, arresting its developer in Indonesia. This disruption is significant due to Kratos' extensive use, with customers allegedly conducting around 15,000 phishing campaigns monthly across 35 countries.