German and US authorities took down more than 200 servers and arrested the platform's developer in Indonesia, but the security experts assessing the takedown agree the 1,800 customers who bought Kratos are already shopping for a replacement.
What happened
German and US law enforcement have dismantled the infrastructure behind Kratos, a phishing-as-a-service platform authorities describe as one of the world's most widely used criminal phishing services. According to BleepingComputer, the operation, led by Frankfurt's Central Office for Combating Internet Crime and Germany's Federal Criminal Police Office, neutralized more than 200 servers and resulted in the arrest of Kratos's alleged developer and technical administrator in Indonesia. German authorities put the number of Kratos customers at more than 1,800 and said it runs roughly 15,000 phishing campaigns per month against victims across 35 countries, mostly in Europe and the United States. Investigators estimate the platform's operator earned at least $350,000 since 2024 from subscription fees.
Going deeper
Kratos functioned as what BKA officials called a criminal digital construction kit, letting subscribers build convincing fake Microsoft login pages without any coding skill of their own. According to The Hacker News, the platform ran like a franchise, with customers paying in cryptocurrency and managing their campaigns through a dedicated website and a Telegram shop. The fraudulent pages captured usernames, passwords, and session cookies from victims, giving attackers the ability to bypass multi-factor authentication and take over Microsoft 365 accounts directly. Microsoft has separately tracked the same underlying kit under the name SneakyLog since early 2025, having previously caught the platform being used to generate phishing campaigns disguised as fake W-2 tax forms targeting US citizens.
What was said
Carsten Meywirth, head of the BKA's cybercrime department, stated in the official BKA announcement that anyone stealing login credentials through fake websites should not feel safe, calling the action against Kratos evidence that even highly professional phishing infrastructure can be effectively dismantled. Frank Dickson, group VP for security at IDC, told CSO Online that the takedown removes infrastructure rather than intellectual property: "PhaaS kits get cloned, forked and resold routinely, and the 1,800 Kratos customers didn't vanish. They just lost a vendor in a market where vendors get replaced fast."
In the know
Security researchers disagree on Kratos's exact origins, a confusion that shows how fluid this criminal marketplace has become. According to The Register, Microsoft ties Kratos to its own tracked kit SneakyLog, which it believes entered the market in early 2025, while KnowBe4's own investigation dates the first signs of Kratos itself only to January 2026 and disputes any lineage connecting it to SneakyLog or Sneaky2FA at all. That disagreement over naming and origin reflects an industry where rebranding and reselling phishing kits happens continuously, not just in response to a law enforcement raid.
The big picture
For healthcare IT and security teams, this takedown does not mean Microsoft 365 phishing threats have declined. Pieter Arntz, malware intelligence researcher at Malwarebytes, told CSO Online that a rebrand or partial re-emergence of the platform is the historical pattern for PhaaS operations, since the underlying code, customer lists, and operator expertise can survive even when core infrastructure is seized. Noah Kenney, principal consultant at Digital 520, told CSO Online that the 1,800 customers who bought Kratos still hold their target lists and sending infrastructure and are simply shopping for a replacement kit that already exists. Healthcare organizations should treat this as confirmation that fake Microsoft login pages that harvest session cookies remain an active, commercially available threat, not as evidence that the threat has meaningfully receded.
FAQs
What made Kratos different from a typical phishing kit?
Kratos operated as a subscription service with a dedicated website and Telegram shop, letting customers manage their own campaigns without any technical skill of their own. It specifically used an adversary-in-the-middle technique, generating convincing fake Microsoft 365 login pages that captured session cookies in real time, allowing attackers to bypass multi-factor authentication rather than simply stealing a password.
Why do security researchers disagree on whether Kratos is the same kit as SneakyLog or Sneaky2FA?
Phishing-as-a-service kits are frequently rebranded, forked, or resold among different criminal operators, making clean attribution difficult even for researchers actively tracking the same infrastructure. Microsoft, KnowBe4, and other firms arrived at different conclusions about Kratos's origins because each was working from different visibility into the kit's code, customer base, and campaign history.
Why do security experts expect Kratos's 1,800 customers to keep phishing despite the takedown?
The individuals who purchased and used Kratos to run their own campaigns were customers of the platform, not employees of it. Removing the platform's infrastructure does not remove those customers' existing target lists, sending infrastructure, or technical familiarity with running phishing campaigns, all of which they can redirect toward a different kit already available on the market.
What happens to the data recovered from the seized Kratos servers?
Investigators can use the seized servers to identify Kratos's customer base and gather forensic evidence that may support additional arrests and prosecutions beyond the single developer already detained in Indonesia. Analysts have specifically highlighted the customer list as the most valuable outcome of the operation, since it could expose the individuals who bought and operated the phishing campaigns Kratos supported.
What should healthcare organizations do given that MFA-bypassing phishing kits like Kratos remain widely available?
Organizations should prioritize phishing-resistant authentication methods such as FIDO2 hardware keys or passkeys, which are not vulnerable to session cookie theft the way standard MFA codes are. Staff should also be trained to treat any unexpected Microsoft login prompt, especially one arriving through an email link rather than a direct navigation to a known company resource, as a potential phishing attempt regardless of how convincing the page appears.
