サイバーセキュリティ 1 h agoブックマークに追加

200を超えるサーバーが破壊され、開発者とみられる人物がバリで逮捕された:ドイツ警察は、国際連合の支援を受け、Kratos、ヨーロッパの銀行口座を狙う日払いのフィッシングキットの運営を終了させた。
According to The Register (July 21, 2026), an operation coordinated by Germany resulted in the dismantling of Kratos, a phishing-as-a-service (PhaaS) platform. The reported outcome: over 200 servers taken offline and a suspected developer arrested in Indonesia.
PhaaS has industrialized phishing. Like Caffeine, LabHost, 16shop, or Rockstar 2FA before it, Kratos provided its criminal clients with turnkey kits: landing pages mimicking banks, victim management dashboards, real-time 2FA bypass via proxy, and infrastructure rented by the week. The small-time crook only needs to send the SMS; the kit does the rest.
The takedown of a PhaaS is a short-term victory, not a checkmate. Previous instances (LabHost shut down in 2024, Caffeine in 2022) have each been followed by a replacement within a few months—the clientele, demand, and techniques remain. What changes, however, is the barrier to entry for the next operator: each takedown lengthens the intelligence trail (crypto tracing, infrastructure correlation), and an arrested developer is a public lesson for the next ones.
Actions to take now:
Kratos falls; demand does not. The true indicator of progress is not the number of kits shut down, but the number of users migrated to a non-phishable authentication factor. Each passkey deployed is one fewer customer for the next PhaaS.
本記事は人工知能により作成され、人間の編集管理のもとで校閲されています。