Kratos: German police dismantle a phishing-as-a-service kit, a suspected developer arrested in Indonesia

Cybersecurity 3 h agoAdd to bookmarks

Kratos: German police dismantle a phishing-as-a-service kit, a suspected developer arrested in Indonesia
Illustration : Momiji Shirogane

More than 200 servers taken down, a suspected developer arrested in Bali: the German police, supported by an international coalition, put an end to Kratos, a phishing kit rented by the day to target European bank accounts.

Facts

According to The Register (July 21, 2026), an operation coordinated by Germany led to the dismantling of Kratos, a phishing-as-a-service (PhaaS) platform. The reported outcome: more than 200 servers taken offline and a suspected developer arrested in Indonesia.

Analysis

PhaaS has industrialized phishing. Like Caffeine, LabHost, 16shop, or Rockstar 2FA before it, Kratos provided its criminal clients with turnkey kits: landing pages mimicking banks, victim management dashboard, real-time 2FA bypass via proxy, and infrastructure rented by the week. The small-time crook just has to send the SMS; the kit does the rest.

The takedown of a PhaaS is a short-term victory, not a game over. Previous instances (LabHost closed in 2024, Caffeine in 2022) have each been followed by a replacement within a few months - the clientele, demand, and techniques remain. What changes, however, is the entry cost for the next operator: each takedown lengthens the intelligence trail (crypto tracing, infrastructure correlation), and an arrested developer is a public lesson addressed to the next ones.

What to do

To do now:

  • Check your anti-phishing alerts and confirm that your business users know where to report a suspicious email (Outlook / Gmail button, dedicated address).
  • On all banks and critical services: switch to passkeys or FIDO2 hardware keys - they are immune to reverse-proxy 2FA that breaks TOTP and push OTP.
  • Follow the IOCs published by national CERTs (BSI in Germany, ANSSI in France) after the operation: satellite infrastructures that were not seized may still be running for a few days.

Key takeaway

Kratos falls; demand does not. The real indicator of progress is not the number of closed kits, but the number of users migrated to a non-phishable authentication factor. Each deployed passkey is one less customer for the next PhaaS.

Article produced by artificial intelligence, reviewed under human editorial control.

Our newsroom
Was this article helpful?

8 people liked this article

Like
K
Kenji AraiCybersecurity expert
Cybersecurity expert, methodical watcher, never alarmist, always actionable.
Share:
LIVERadio Geek Kitsune
Tap to listen, the same sound for everyone
0··
// Schedule
// all stations
// share a track →
Topics
Explore
Information