Kratos: German police dismantle a phishing-as-a-service kit, a suspected developer arrested in Indonesia

Cybersecurity Jul 22, 2026Add to bookmarks

Kratos: German police dismantle a phishing-as-a-service kit, a suspected developer arrested in Indonesia
Illustration : Momiji Shirogane

More than 200 servers taken down, a suspected developer arrested in Bali: the German police, supported by an international coalition, put an end to Kratos, a phishing kit rented by the day to target European bank accounts.

Facts

According to The Register (July 21, 2026), an operation coordinated by Germany led to the dismantling of Kratos, a phishing-as-a-service (PhaaS) platform. The reported outcome: more than 200 servers taken offline and a suspected developer arrested in Indonesia.

Analysis

PhaaS has industrialized phishing. Like Caffeine, LabHost, 16shop, or Rockstar 2FA before it, Kratos provided its criminal clients with turnkey kits: landing pages mimicking banks, victim management dashboard, real-time 2FA bypass via proxy, and infrastructure rented by the week. The small-time crook just has to send the SMS; the kit does the rest.

The takedown of a PhaaS is a short-term victory, not a game over. Previous instances (LabHost closed in 2024, Caffeine in 2022) have each been followed by a replacement within a few months - the clientele, demand, and techniques remain. What changes, however, is the entry cost for the next operator: each takedown lengthens the intelligence trail (crypto tracing, infrastructure correlation), and an arrested developer is a public lesson addressed to the next ones.

What to do

To do now:

  • Check your anti-phishing alerts and confirm that your business users know where to report a suspicious email (Outlook / Gmail button, dedicated address).
  • On all banks and critical services: switch to passkeys or FIDO2 hardware keys - they are immune to reverse-proxy 2FA that breaks TOTP and push OTP.
  • Follow the IOCs published by national CERTs (BSI in Germany, ANSSI in France) after the operation: satellite infrastructures that were not seized may still be running for a few days.

Key takeaway

Kratos falls; demand does not. The real indicator of progress is not the number of closed kits, but the number of users migrated to a non-phishable authentication factor. Each deployed passkey is one less customer for the next PhaaS.

Resources, try it

Article produced by artificial intelligence, reviewed under human editorial control.

Our newsroom
Was this article helpful?

8 people liked this article

Like
K
Kenji AraiCybersecurity expert
Cybersecurity expert, methodical watcher, never alarmist, always actionable.
Share:
LIVERadio Geek Kitsune
Tap to listen, the same sound for everyone
0··
// Schedule
// all stations
// share a track →
Topics
Explore
Information