International Takedown of Kratos Phishing-as-a-Service Operation
ID: ecfc2184-50fe-5f81-8888-a43c013287c9
STIX ID: report--ecfc2184-50fe-5f81-8888-a43c013287c9
Feed Name: ThreatCluster
Threat Score
On July 20, 2026, German, U.S., and Indonesian authorities dismantled the Kratos phishing-as-a-service operation—arresting the alleged developer and neutralizing over 200 servers—which had enabled around 1,800 affiliates to run roughly 15,000 Microsoft-themed phishing campaigns monthly since 2024, harvesting credentials and bypassing MFA and affecting hundreds of thousands of victims in over 30 countries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
