"Our approach of disruptive law enforcement works: In addition to the primary task of identifying and prosecuting the accused, we have once again succeeded in dismantling a criminal online service and thus contributing to greater cybersecurity," said Dr Benjamin Krause, head of the Central Office for Combating Internet Crime (ZIT) at the Frankfurt am Main Public Prosecutor's Office.
ZIT and BKA say they neutralized Kratos' infrastructure
German authorities announced a coordinated operation that they say neutralized the main infrastructure supporting the Kratos phishing-as-a-service (PhaaS) kit. The Central Office for Combating Internet Crime (ZIT) in Frankfurt am Main and the Federal Criminal Police (BKA) described Kratos as "one of the most widespread and dangerous PhaaS kits on the market." Authorities reported that the operation neutralized more than 200 servers, though the BKA declined to explain how that neutralization was achieved.
The announcement also noted international support: the takedown was "supported by the US and Indonesia." In Indonesia, authorities said they arrested the Kratos kit's alleged "developer and technical administrator." The German announcement did not say whether additional individuals are being pursued.
How Kratos worked: credential harvesting, session cookies, and Microsoft lures
The ZIT and BKA said Kratos enabled low-skill criminals to harvest credentials — including passwords and session cookies — and to bypass multi-factor authentication (MFA) by presenting convincing Microsoft-themed phishing pages. The authorities specifically mentioned fake Microsoft authentication pages among the templates offered by Kratos.
Security vendors have documented broader lure themes attributed to Kratos, with Heal Security reporting lures around SharePoint, OneDrive, Microsoft Forms, Canva and Tilda as recently as July 16. KnowBe4's February investigation added Adobe-themed lures to that list. Microsoft, which said Kratos was also known as SneakyLog, reported that SneakyLog had been used to generate phishing campaigns targeting US citizens with fake W-2 tax forms.
Scale, earnings, and criminal adoption — the numbers the authorities released
German authorities provided concrete figures to describe Kratos' reach. They said criminals using Kratos targeted hundreds of thousands of victims across more than 30 countries. More than 1,800 criminal enterprises are estimated to have used the kit, which the authorities said supported roughly 15,000 phishing campaigns per month — "each individual campaign had the potential to harm several thousand recipients worldwide," the statement said.
The operation behind Kratos allegedly earned more than €300,000 (reported as $342,000) since 2024, according to the ZIT and BKA. Those totals, the agencies argue, illustrate both the profitability of PhaaS models and the scale of harm when professionalized phishing infrastructure is widely available.
Aliases, timelines, and clash in open-source reporting
German authorities referred to the kit only as Kratos, but open-source reporting has tied the product to names such as SneakyLog and Sneaky 2FA. Microsoft believes SneakyLog entered the phishing kit market as of early 2025, while KnowBe4 said the first signs of Kratos only emerged in January 2026 and described the product as evolving from a family of commercial trojans and infostealers. KnowBe4 did not mention SneakyLog or Sneaky 2FA as part of Kratos' past, muddying a single, consistent timeline for the kit's origins.
That lack of unanimity in public reporting stands in contrast to the authorities' detailed operational figures and to vendors' observations of the kit's lure templates and target sectors. Microsoft identified manufacturing, retail, and healthcare as the main US target industries, while ANY.RUN reported that European victims included industrial organizations, law firms, polytechnic institutions, schools, SMBs, and others.
What this means for technologists, policymakers, and affected enterprises
- Technologists and security teams: The takedown demonstrates active law enforcement methods can disrupt PhaaS infrastructure; teams will want to monitor for re-emergence of similar kits under different names and validate that MFA and session management protections are resilient to credential- and cookie-harvesting techniques the authorities described.
- Policymakers and law enforcement: The international cooperation noted — support from the US and arrests in Indonesia — underscores cross-border coordination as a necessary element in tackling commercialized phishing services, and provides a recent example of neutralizing infrastructure rather than limiting response to post-compromise remediation.
- Affected enterprises and procurement leaders: The authorities' attribution of victim industries and the list of lure templates signal that Microsoft-branded pages and common cloud service workflows remain popular vectors; organizations in the named sectors should review user education, detection of credential-exfiltration patterns, and contractual expectations of providers used to host or deliver critical infrastructure.
Carsten Meywirth, head of the cybercrime department at the BKA, framed the takedown as both operational and symbolic: "Anyone who steals login credentials online using fake websites shouldn't feel safe. The success against the Kratos phishing kit shows that even highly professional phishing infrastructures can be effectively combated. This is pioneering work and a clear signal to other cyber actors – phishing will not go unpunished and will be consistently fought by the BKA."
The takedown leaves open practical questions the authorities did not address in their announcement: whether additional arrests are planned, how long the neutralization of more than 200 servers will be sustained, and how quickly the criminal ecosystem of more than 1,800 customers will pivot to alternative kits. For now, German authorities and their partners want the message to be plain: the core infrastructure behind Kratos is offline and the people behind it are in investigators' sights.




