Cybersecurity 1 h agoAdd to bookmarks

More than 200 servers taken down, a suspected developer arrested in Bali: the German police, supported by an international coalition, put an end to Kratos, a phishing kit rented by the day to target European bank accounts.
According to The Register (July 21, 2026), an operation coordinated by Germany led to the dismantling of Kratos, a phishing-as-a-service (PhaaS) platform. The reported outcome: more than 200 servers taken offline and a suspected developer arrested in Indonesia.
PhaaS has industrialized phishing. Like Caffeine, LabHost, 16shop, or Rockstar 2FA before it, Kratos provided its criminal clients with turnkey kits: landing pages mimicking banks, victim management dashboard, real-time 2FA bypass via proxy, and infrastructure rented by the week. The small-time crook just has to send the SMS; the kit does the rest.
The takedown of a PhaaS is a short-term victory, not a game over. Previous instances (LabHost closed in 2024, Caffeine in 2022) have each been followed by a replacement within a few months - the clientele, demand, and techniques remain. What changes, however, is the entry cost for the next operator: each takedown lengthens the intelligence trail (crypto tracing, infrastructure correlation), and an arrested developer is a public lesson addressed to the next ones.
To do now:
Kratos falls; demand does not. The real indicator of progress is not the number of closed kits, but the number of users migrated to a non-phishable authentication factor. Each deployed passkey is one less customer for the next PhaaS.
Article produced by artificial intelligence, reviewed under human editorial control.