logo

International Takedown of Kratos Phishing-as-a-Service Operation

ID: ecfc2184-50fe-5f81-8888-a43c013287c9

STIX ID: report--ecfc2184-50fe-5f81-8888-a43c013287c9

Feed Name: ThreatCluster

Threat Score
75/100

Date Published: 2026-07-21

Date Updated: 2026-07-22

...
...

On July 20, 2026, German, U.S., and Indonesian authorities dismantled the Kratos phishing-as-a-service operation—arresting the alleged developer and neutralizing over 200 servers—which had enabled around 1,800 affiliates to run roughly 15,000 Microsoft-themed phishing campaigns monthly since 2024, harvesting credentials and bypassing MFA and affecting hundreds of thousands of victims in over 30 countries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.