Summary
- German and US authorities disrupted Kratos, a phishing-as-a-service kit targeting Microsoft authentication pages.
- Investigators say victims were spread across more than 30 countries, with concentration in Europe and the United States.
- The case reinforces the limits of ordinary MFA where adversary-in-the-middle phishing captures live sessions.
Germany’s Federal Criminal Police Office and US law enforcement have disrupted the central infrastructure behind Kratos, a phishing-as-a-service operation used to steal credentials through fake Microsoft authentication pages.
The operation was carried out with the Frankfurt public prosecutor’s cybercrime unit, known as ZIT, and US partners. Investigators described Kratos as one of the world’s most widely used criminal phishing services, with victims across more than 30 countries and a strong concentration in Europe and the United States. Indonesian authorities arrested the alleged developer and technical administrator, while central infrastructure was taken offline.
Kratos was built as a rentable toolkit. Its operators provided a digital platform that allowed other criminals to create and manage convincing phishing pages, then run campaigns against real users. Reporting on the German notice said the service supported about 15,000 phishing campaigns each month and had generated more than €300,000 for its operators since 2024.
The enterprise risk sits in the authentication flow. Phishing kits that imitate Microsoft 365 login pages do not only harvest passwords; more advanced versions can also capture session cookies during adversary-in-the-middle attacks. Once a live session is taken, ordinary multi-factor authentication no longer gives the protection many risk registers assume. The attacker may not need the victim’s second factor again if the session remains valid.
Microsoft 365 has become a core business operating layer for email, files, calendars, collaboration, identity, and administration. A stolen session can expose mailboxes, internal documents, contact networks, invoices, executive communications, and cloud administrative portals. From there, attackers can move into business email compromise, internal phishing, data theft, and payment fraud.
The takedown reduces active criminal infrastructure, but it does not remove exposure created before the operation. Organisations targeted by Kratos-linked campaigns may still need to review sign-in logs, revoke suspicious sessions, reset credentials, inspect mailbox rules, examine OAuth grants, and look for unusual access to files and administrative functions. Token theft is not always resolved by a password change.
The operation also shows why phishing-as-a-service remains durable. By packaging templates, hosting, campaign tools, credential capture, and user support, criminal developers reduce the skill required to run attacks at scale. A law enforcement action can break a specific service, seize servers, and disrupt customers, but techniques, code, and demand can reappear through successor brands and copied infrastructure.
Identity controls need to reflect that operating model. Phishing-resistant authentication, conditional access, device binding, continuous session evaluation, rapid token revocation, and monitoring for abnormal session use all carry more value than treating staff awareness as the main line of defence. Awareness may reduce some compromise, but it cannot reliably defeat a well-run proxy phishing kit designed to capture live authentication.
Kratos gives defenders a set of leads to investigate and a reminder that session security now sits at the centre of identity resilience. MFA remains necessary, but interceptable sessions and reusable tokens leave a gap that criminal services are built to exploit.



