Kratos phishing kit collapsed as German, US, and Indonesia police took down 200+ servers
A cross-border operation arrested the alleged developer and technical administrator, disrupting a PhaaS used for thousands of monthly campaigns.

German authorities, with support from the US and Indonesia, say they dismantled the main infrastructure behind the Kratos phishing-as-a-service kit. The operation includes the arrest in Indonesia of the kit's alleged developer and technical administrator, after officials described it as one of the most widespread and dangerous PhaaS offerings.
German authorities say they neutralized the main infrastructure behind the Kratos phishing-as-a-service kit after a cross-border operation supported by the US and Indonesia. The takedown, led through Frankfurt am Main's Central Office for Combating Internet Crime (ZIT) and the Federal Criminal Police (BKA), also resulted in Indonesia arresting the kit's alleged “developer and technical administrator.”
This matters for a simple reason: German officials described Kratos as one of the most widespread and dangerous PhaaS kits on the market, and they link it to large-scale credential theft designed specifically to bypass multi-factor authentication. According to the ZIT and BKA, Kratos let low-skill cybercriminals harvest credentials such as passwords and session cookies, then feed them to “convincing Microsoft-themed phishing pages” to defeat MFA. In the operational details German authorities provided, the kit’s users allegedly targeted hundreds of thousands of victims across more than 30 countries.
The scale did not come from a handful of elite attackers. German authorities estimate that more than 1,800 criminal enterprises used Kratos, which they say was responsible for around 15,000 phishing campaigns per month. Put another way, the kit acted like a distribution platform, not just a tool. German authorities also said “each individual campaign had the potential to harm several thousand recipients worldwide,” a line that is less about rhetoric and more about the math of modern inbox-driven attacks. If one campaign can reach thousands, then a platform that can power thousands of campaigns per month quickly becomes an infrastructure problem for entire regions.
On the money side, the operation allegedly generated more than €300,000 (about $342,000) since 2024, according to the ZIT and BKA. The announcement did not specify whether other people are under pursuit. Still, for boards and risk committees, the arrest is the headline. It suggests law enforcement can go after not only victims and one-off phishing lures, but also the supply chain that makes phishing industrial.
Technically, German officials said they neutralized more than 200 servers, though the BKA declined to explain how. Methods from previous takedowns mentioned in the reporting offer a practical glimpse of how this disruption can work: officers can hand legal warrants to infrastructure providers, including the kit’s chosen hosting company, and coordinate with ISPs to “null-route or sinkhole” traffic associated with suspect IP addresses. The second-order implication is that disruption can be layered. Even if attackers shift domains or templates quickly, removing hosting, rerouting traffic, and breaking the operational backbone can increase attacker cost and slow down campaign throughput.
The story also runs straight into the identity and template ecosystem of credential theft. German authorities, per the reporting, referred to the PhaaS kit only as Kratos, though open source reporting has tied it to products previously sold under names such as SneakyLog and Sneaky 2FA. The German and BKA statement itself mentioned only fake Microsoft authentication pages among Kratos’s templates. That aligns with Microsoft’s earlier reporting that SneakyLog had been used to generate phishing campaigns targeting US citizens with fake W-2 tax forms.
Where it gets messy, and why leaders should care, is timing and evolution. Security shops including Heal Security reported as recently as July 16 that Kratos offered customers lures themed around multiple websites, including SharePoint, OneDrive, Microsoft Forms, Canva, Tilda, and more. KnowBe4 added Adobe lures to the list with its own investigation in February, which also raised uncertainty about when the kit first hit the market. Microsoft believes Kratos, known by it as SneakyLog, entered the phishing kit market as of early 2025. KnowBe4 said the first signs of Kratos emerged in January 2026, and it did not mention SneakyLog or Sneaky 2FA as part of Kratos’s past. KnowBe4 instead argued the kit evolved from a previous life as a family of commercial trojans and infostealers.
Regardless of the exact origin story, the operational focus appears geographically consistent. Open source reporting cited in the article says targets of Kratos customers are primarily based in the US and Europe. Microsoft identified manufacturing, retail, and healthcare as main target industries in the US. In Europe, industrial organizations, law firms, polytechnic institutions, schools, SMBs, and others have been attacked, according to ANY.RUN. That mix is a reminder that PhaaS is designed to scale across industries that share one trait: they rely on login credentials, and they are tempting targets for fraud that looks normal enough to slip past employees and even some security controls.
Dr Benjamin Krause, head of the ZIT at the Frankfurt am Main Public Prosecutor's Office, said, “Our approach of disruptive law enforcement works: In addition to the primary task of identifying and prosecuting the accused, we have once again succeeded in dismantling a criminal online service and thus contributing to greater cybersecurity.” Carsten Meywirth, head of the cybercrime department at the BKA, added that anyone who steals login credentials using fake websites “shouldn't feel safe,” and that the success against the Kratos phishing kit shows “even highly professional phishing infrastructures can be effectively combated.” For executives, the strategic takeaway is less about celebration and more about pressure testing: if credential-phishing kits can be built to bypass MFA and scale through thousands of campaigns, resilience has to be operational, not just policy. The disruption of more than 200 servers is a win, but the ecosystem will keep trying to rebuild. The companies that benefit most are the ones treating credential security, detection, and incident readiness as a continuous system, not a quarterly checkbox.
This story's Key Insights and Take-aways are locked.
Create a free account to unlock Executive Actions for one credit.
Register to UnlockAlways free for Executives Club members. Join the Club
More in Business

Anthropic’s Levant Alpöge cracks the Jacobian conjecture after 87 years
A Harvard valedictorian used Claude to hit a 1939 breakthrough, but the missing “why” is the real problem.

Uber buys Delivery Hero for nearly $15B, vaulting to top food delivery outside China
The deal doubles Uber's dual-services footprint and pushes a ride-and-eats bundling play into 50 more markets.

Epic and Google drop settlement bid, forcing rival Android app stores by July 22
Google told the court it is ready to carry third-party app stores starting Wednesday, July 22.

