Authorities in Germany and the US have shut down the main infrastructure of Kratos, a phishing-as-a-service (PhaaS) platform used by cybercriminals worldwide.
During the operation, law enforcement seized more than 200 servers. The platform's developer was arrested in Indonesia. The investigation was led by Germany's Federal Criminal Police Office (BKA) and the Frankfurt Prosecutor General's Office, with support from US authorities.
Officials said Kratos was one of the world's largest phishing platforms, with victims in 35 countries. More than 1,800 criminal customers reportedly used the service to launch around 15,000 phishing campaigns each month.
Kratos allowed attackers to create fake Microsoft login pages that stole email addresses and passwords. Stolen accounts were then used for crimes such as account takeovers, data theft, business email compromise (BEC), and sending phishing messages to victims' contacts.
Authorities estimate the platform's operator earned at least €300,000 ($342,000) in subscription fees since 2024.