German Police Take Down Kratos Phishing-as-a-Service Platform — But Is the Threat Really Gone?

A coordinated international crackdown seized over 200 servers and arrested a key developer, yet cybersecurity experts warn the broader phishing economy will barely flinch

German Police Take Down Kratos Phishing-as-a-Service Platform — But Is the Threat Really Gone?

What Was Kratos and Why Did It Matter to Enterprise Security?

German law enforcement has announced the dismantling of Kratos, one of the most significant phishing-as-a-service (PhaaS) platforms operating on the criminal market. In a coordinated international operation involving agencies from the United States, Indonesia, and several other countries, authorities seized more than 200 servers powering the Kratos infrastructure and arrested a developer and technical administrator of the platform in Indonesia. The German Federal Criminal Police Office (BKA) declared that "Kratos-supported phishing campaigns can no longer be carried out" — a bold claim that the cybersecurity community is treating with measured skepticism.

For IT decision-makers, privacy professionals, and small business owners who rely on cloud services, the Kratos takedown is a useful case study in how modern cybercrime operates — and why dismantling a single vendor rarely translates to lasting relief. Kratos was not just a hacking group. It was a commercial service provider selling ready-made phishing kits to roughly 1,800 paying customers, allowing even technically unsophisticated criminals to launch highly convincing attacks against corporate targets. According to reporting by CSO Online, Kratos specialized in adversary-in-the-middle (AiTM) techniques — generating fake Microsoft 365 login pages capable of harvesting session tokens and bypassing multi-factor authentication (MFA).

Cybersecurity analyst monitoring phishing infrastructure on multiple screens
Law enforcement agencies collaborated internationally to dismantle the Kratos phishing infrastructure

The platform was tracked under multiple names across the security research community — Microsoft called it SneakyLog, others linked it to Sneaky 2FA — a naming inconsistency that itself reveals how rapidly these kits are copied, rebranded, and redistributed. The business model mirrors legitimate software-as-a-service: subscription access, regular updates, and customer support for criminal operators. This commoditization of phishing tools is precisely what makes the broader PhaaS ecosystem so resilient to individual law enforcement actions.

How Kratos Bypassed MFA and Targeted Microsoft 365 Users

The technical sophistication of Kratos is worth understanding in detail, particularly for IT administrators and security architects who may be reviewing their defenses in the wake of this news. Rather than relying on simple credential harvesting — capturing usernames and passwords through fake login pages — Kratos operated as an adversary-in-the-middle proxy. In this attack model, the phishing page sits between the victim and the legitimate Microsoft 365 login server, relaying traffic in real time and capturing not just credentials but the authenticated session token issued after MFA is completed.

This means that even organisations with MFA enabled across their Microsoft 365 tenants were vulnerable. Once an attacker possesses a valid session token, they can access email, SharePoint, Teams, and connected business applications without ever needing to know the victim's password or second factor. As noted by Frank Dickson, group VP for security at IDC, this technique is "the exact mechanism behind a lot of the business email compromise activity of the past two years." Business email compromise (BEC) remains one of the costliest forms of cybercrime globally — the FBI's Internet Crime Complaint Center consistently reports BEC losses running into billions of dollars annually.

1,800Kratos paying customers at time of takedown
200+Servers seized by law enforcement
1Developer arrested in Indonesia
0Customer arrests reported so far

For developers building or maintaining SaaS applications, the AiTM threat model is particularly instructive. Traditional MFA — time-based one-time passwords (TOTP), SMS codes, or even app-based push notifications — provides no protection against session token theft. More phishing-resistant options such as FIDO2/WebAuthn passkeys, hardware security keys, and certificate-based authentication are the technical countermeasures that genuinely defeat AiTM proxies, because they bind authentication cryptographically to the legitimate origin domain. Enterprises still relying on legacy MFA should treat this takedown as a prompt to reassess their authentication architecture, regardless of how long Kratos remains offline.

Why Security Experts Say the Phishing-as-a-Service Economy Will Recover Quickly

The cybersecurity community's reaction to the Kratos takedown has been notably cautious. Across the board, analysts acknowledge the operational significance of seizing centralized infrastructure while questioning whether the disruption will prove durable. The core argument is structural: Kratos was a vendor, not the phishing operation itself.

"The 1,800 customers who bought it still have their target lists, their sending infrastructure and whatever access they had already established. The tooling went dark, but the people phishing your employees last week are still working, shopping for a replacement that already exists."

— Noah Kenney, Principal Consultant, Digital 520

This framing distinguishes the Kratos takedown from more impactful law enforcement actions against ransomware groups, where the criminal operators themselves are often directly implicated and arrested. With PhaaS, the platform developer and the attackers are entirely separate parties connected only through a commercial transaction. Seizing Kratos removes a tool from criminal hands — but those hands remain free, funded, and motivated.

Assaf Morag, a cybersecurity researcher at Flare, characterised the German action as "symbolic" given Kratos' reach within phishing circles, arguing that "demand is likely to shift to competing providers, allowing the ecosystem to recover even if this particular operation has been disrupted." This mirrors the well-documented pattern following previous PhaaS and cybercrime-as-a-service takedowns, where competitor platforms typically absorb displaced customers within days or weeks. Research published by Europol's Internet Organised Crime Threat Assessment has repeatedly highlighted this marketplace resilience as one of the defining challenges facing law enforcement in the cybercrime space.

Flavio Villanustre, CISO for the LexisNexis Risk Solutions Group, put it bluntly: "For each criminal organization that is dismantled, ten new ones pop out of nowhere. Unless there is a coordinated international effort by more than a few countries, this is a whack-a-mole exercise." He compared the structure of these criminal networks to the mythological Lernaean Hydra — cut off one head and two grow back — arguing that decentralised leadership and organic succession make complete elimination essentially impossible.

The Real Win: What Law Enforcement Can Do With Kratos Customer Data

While experts are measured about the operational disruption, there is genuine enthusiasm in the security community about one potential outcome: the intelligence value locked inside the seized servers. A PhaaS platform with 1,800 active subscribers necessarily holds extensive records — customer identities or pseudonyms, payment histories, target organisation lists, campaign logs, and potentially communications between the platform operators and their clients.

Digital forensics investigator analysing seized server data
Data from seized servers may give investigators direct leads to Kratos customers running active phishing campaigns

"Kratos operated in the adversary-in-the-middle category, generating convincing fake Microsoft 365 login pages that harvest session tokens and step past MFA. I would love to see what law enforcement does with the customer list. That, my friend, is gold."

— Frank Dickson, Group VP for Security, IDC

This is where the real investigative leverage lies. If law enforcement agencies from the US, Germany, and Indonesia can cross-reference customer account data with financial transaction records, cryptocurrency wallets, and IP logs, they may be able to identify and prosecute the actual phishing operators — the 1,800 customers — rather than just the platform provider. This would represent a qualitatively different kind of disruption, one that targets the demand side of the PhaaS economy rather than just the supply side.

For privacy professionals and GDPR compliance officers, this dimension of the story also raises interesting questions. The servers reportedly hosted extensive data about phishing campaigns — which organisations were targeted, which employees were deceived, which accounts were compromised. Depending on how that data was structured and what it reveals about past breaches, there could be notification obligations triggered for affected organisations across EU member states under GDPR Article 33. Companies should be monitoring law enforcement communications carefully in the coming weeks for any indication that their users or employees featured in Kratos campaign logs.

Understanding the Broader PhaaS Threat Landscape in 2024

The Kratos case is not an isolated incident — it reflects a maturing criminal marketplace in which technical expertise has been fully decoupled from criminal intent. According to analysis from Microsoft's Security Intelligence team, adversary-in-the-middle phishing toolkits have become among the fastest-growing categories of cybercrime tooling, with dozens of platforms now offering subscription-based access to MFA-bypass capabilities.

PhaaS CharacteristicTraditional PhishingKratos-Style PhaaS
Technical skill requiredHighLow — kit handles complexity
MFA bypass capabilityNoYes — session token theft
Operator modelSelf-built infrastructureSubscription with support
Kit longevity after takedownNot applicableCode survives; easily forked
Primary targetVariedMicrosoft 365 enterprise accounts
Arrest impactDisruptiveLimited — customers unaffected
Originally reported by CSO Online. Summarised and curated by European Purpose.