German and U.S. law enforcement dismantle the core infrastructure behind Kratos, a phishing-as-a-service (PhaaS) platform used by criminals worldwide. Authorities describe Kratos as one of the most widely used criminal phishing kits and as operating through an organized backend that supports large-scale campaigns. The takedown is led by Germany’s Frankfurt public prosecutor’s cybercrime unit (ZIT) and the Federal Criminal Police Office (BKA), with cooperation from U.S. law enforcement agencies. German investigators say the platform is built to target Microsoft 365 accounts by stealing sessions and helping bypass multi-factor authentication (MFA).

Investigators also arrest the individual they allege is the platform’s developer and administrator. The arrest takes place in Indonesia, carried out by local police, according to the reporting. Authorities describe the operation as disrupting the infrastructure used to launch and manage phishing campaigns, which they say number in the tens of thousands per month. Officials publicly present the action as a cross-border operation involving German prosecutors, German police, U.S. counterparts, and Indonesian authorities.