"One of the world’s most widely used criminal phishing services," authorities said — and they have taken its central plumbing offline.
Kratos: a phishing-as-a-service toolkit that impersonated Microsoft
Kratos was a commercial phishing toolkit rented to criminal customers to create and manage fake Microsoft authentication pages. The kit supplied convincing login forms engineered to capture email addresses and passwords; successful captures enabled attackers to hijack Microsoft accounts and, according to the German Federal Police (BKA), to "commit further crimes." BKA's description of post-compromise activity includes business email compromise, data theft, account takeover, and new phishing attacks that targeted the victims' contacts.
Scale of abuse: 1,800 customers, 15,000 campaigns per month, victims in 35 countries
The BKA said the platform had reach across 35 countries, with confirmed victims in Europe and the United States. "Authorities believe that more than 1,800 criminal customers purchased Kratos and used it to conduct roughly 15,000 phishing campaigns per month," the announcement stated, adding that "each campaign had the potential to affect several thousand recipients worldwide." Those figures place Kratos among the largest phishing-as-a-service operations described by the announcing agencies.
Operation Olympus Blade: servers seized, developer arrested
Frankfurt’s Prosecutor General Office (ZIT) and Germany’s Federal police (BKA), working in collaboration with U.S. law enforcement, led the action that dismantled Kratos' central infrastructure. Authorities seized more than 200 servers during the operation and added a seizure banner to the service's website under the name Operation Olympus Blade. The banner stated that domain ownership has now been transferred to the FBI. Separately, the developer — described in reporting as the technical administrator — was arrested in Indonesia.
Seized infrastructure and forensic leads
With key parts of Kratos' infrastructure offline and more than 200 servers in custody, investigators say they can now retrieve forensic evidence from the seized systems. BKA noted that those artifacts may lead to the identification of customers who rented the service. The agencies also reported a monetary trail: they estimate the owner of the service made at least €300,000 ($342,000) since 2024 from subscription fees.
What this means for security teams, affected enterprises, and threat actors
- Security teams: The takedown removes an available toolkit that produced high-volume phishing campaigns, and seized servers may supply forensic indicators that defenders can incorporate into detection and hunting. BKA stated that, with the arrest of the technical administrator and the shutdown of key parts of its infrastructure, these phishing campaigns can no longer continue.
- Affected enterprises and end users: Organizations and individuals targeted by Kratos-enabled campaigns faced account hijack and secondary crimes including business email compromise and data theft. The record of confirmed victims across 35 countries indicates both cross-border reach and a need to review account compromises tied to Microsoft authentication prompts.
- Threat actors and criminal customers: The marketplace that supplied ready-made Microsoft credential phish pages has been disrupted and the developer detained; however, the availability of seized forensic evidence creates a new risk for customers who used Kratos.
The operation removes a widely used criminal service from the web and places its infrastructure in the hands of investigators. Authorities emphasize the investigative value of the seized servers: they could identify customers and provide leads into the downstream crimes enabled by captured credentials. The seizure banner transferring domain ownership to the FBI signals ongoing cross-border cooperation; what follows will be the forensic work needed to trace campaigns, attribute customer accounts and, where warranted, pursue new arrests or charges.
Original story: Police dismantle Kratos phishing platform, arrest developer — BleepingComputer




