Overview
- Investigators shut down more than 200 servers and rendered Kratos’s central infrastructure inoperative, officials said Monday.
- Local authorities in Indonesia arrested the platform’s developer and technical administrator after coordinated work with German and U.S. partners.
- Kratos operated as a Phishing-as-a-Service toolkit that let customers build fake Microsoft sign-in pages to capture passwords, email addresses, and session cookies that could bypass two-factor protections.
- German prosecutors have opened investigations for running a commercial criminal trading platform, falsifying evidence-bearing data, and preparing computer fraud while Microsoft will notify affected users.
- Authorities say Kratos was rented to about 1,800 criminal operators and powered roughly 15,000 phishing campaigns per month since late 2024, and investigators will now search for remnants, affiliates, and victims across more than 30 countries.