Police dismantle Kratos phishing platform, arrest developer
Authorities in Germany and the U.S. dismantled the central infrastructure of Kratos, a phishing-as-a-service (PhaaS) platform with global reach, and its developer was arrested in Indonesia.
Intelligence analysis by Llama

The operation, led by Frankfurt’s Prosecutor General Office (ZIT), Germany’s Federal police (BKA), and U.S. law enforcement agencies, seized more than 200 servers, effectively disrupting the malicious service and rendering it inoperable.
Imagine you're trying to log in to your email account, but the website looks exactly like the real one. That's what the Kratos phishing platform did. It created fake websites that looked real, and people fell for it. The good news is that the police caught the people behind it and shut down the platform, so it can't hurt anyone else.
Analysis
A Global Reach, a Local Impact
The Kratos phishing platform, with its global reach and confirmed victims in 35 countries, particularly in Europe and the United States, is a stark reminder of the severity of phishing attacks. The platform's infrastructure, which allowed threat actors to create and manage fake Microsoft authentication pages, was rented to cybercriminals for phishing attacks. These attacks had the potential to affect several thousand recipients worldwide, with each campaign designed to steal email addresses and passwords, enabling the attackers to hijack Microsoft accounts.
The Economic Impact
The authorities estimate that the owner of the service made at least €300,000 ($342,000) since 2024, from subscription fees to the Kratos platform. This financial gain is a testament to the lucrative nature of phishing attacks, which can be used to commit further crimes, such as business email compromise, data theft, account takeover, and phishing attacks targeting the victims' contacts.
The Road Ahead
With the arrest of the technical administrator and the shutdown of key parts of its infrastructure, BKA states that these phishing campaigns can no longer continue. However, the dismantling of Kratos is just one step in the fight against phishing attacks. It is essential for individuals and organizations to remain vigilant and take proactive measures to protect themselves against these types of attacks.
Key points
- Authorities in Germany and the U.S. dismantled the central infrastructure of Kratos, a phishing-as-a-service (PhaaS) platform with global reach.
- The developer of Kratos was arrested in Indonesia.
- The operation seized more than 200 servers, effectively disrupting the malicious service and rendering it inoperable.
- The authorities estimate that the owner of the service made at least €300,000 ($342,000) since 2024, from subscription fees to the Kratos platform.
The dismantling of Kratos and the arrest of its developer are significant steps in combating phishing attacks. This development demonstrates the effectiveness of international cooperation and the determination of law enforcement agencies to protect individuals and organizations from these types of attacks.
The dismantling of Kratos may not be the end of phishing attacks. New platforms and services may emerge, and individuals and organizations must remain vigilant and take proactive measures to protect themselves against these types of attacks.
Market signals
- XAU The increased risk of phishing attacks may drive demand for safe-haven assets like gold.
AI-generated analysis of potential market relevance. Not financial advice.



