German and US police pull the plug on Kratos, a phishing kit rented to 1,800 crooks
Investigators seized more than 200 servers and arrested the developer in Indonesia, ending a service that ran roughly 15,000 fake Microsoft login campaigns every month.

Key points
- German and US law enforcement dismantled the Kratos phishing service and seized more than 200 servers in a joint operation announced this week.
- The developer of Kratos was arrested in Indonesia, and the service's website now carries an FBI seizure notice under the banner Operation Olympus Blade.
- Germany's Federal Criminal Police (BKA) says around 1,800 paying customers used Kratos to run about 15,000 phishing campaigns per month across 35 countries.
- The owner is estimated to have earned at least 300,000 euros (about 342,000 US dollars) in subscription fees since 2024.
- Kratos specialised in fake Microsoft login pages designed to steal email addresses and passwords.
Police in Germany and the United States have shut down one of the busiest phishing services on the internet, a rental kit called Kratos.
Phishing, for anyone who has not run into the word before, is when criminals send fake emails or set up fake login pages to trick people into typing in their real passwords. Kratos was a ready-made toolkit for doing exactly that, sold by subscription to other criminals. Think of it as a criminal software-as-a-service business, the same rental model used by legitimate cloud apps, but pointed at your inbox.
The takedown was led by the Frankfurt Prosecutor General's Office (ZIT) and Germany's Federal Criminal Police (BKA), working with US agencies. The operation, first reported by BleepingComputer, was given the name Operation Olympus Blade. Investigators pulled more than 200 servers offline and arrested the person they say built and ran the platform. He was picked up in Indonesia.
Visit the Kratos website today and you get an FBI seizure notice instead of a login screen.
What did Kratos actually do?
It sold convincing fake Microsoft sign-in pages to criminals who did not want to build their own. A subscriber would send a target a link, often hidden inside an email that looked like a routine Microsoft 365 notification. The victim clicked, saw what looked like the normal Microsoft login box, and typed in their work email and password. Those credentials went straight to the attacker.
Once inside a Microsoft account, criminals typically read the victim's email, hunt for invoices to redirect, reset passwords on other services, or send more phishing emails from the trusted account to trick the victim's colleagues and customers. In the industry this follow-on fraud is called business email compromise, which is just a formal name for stealing money by pretending to be someone you work with.
BKA describes Kratos as "one of the world's most widely used criminal phishing services." Confirmed victims sit across 35 countries, with heavy concentrations in Europe and the United States. Each campaign, police say, could reach several thousand people.
What should ordinary people do now?
If you use a work or school Microsoft account, this is a good moment to check two things.
First, turn on multi-factor authentication if you have not already. That is the extra code from an app or text message that most workplaces now require. It would have stopped many Kratos victims from losing their accounts even after they typed the password into a fake page.
Second, be suspicious of any Microsoft login page you reach by clicking a link in an email. Type the address yourself, or use a saved bookmark. Password managers help here too: they refuse to fill in credentials on a lookalike domain, because they notice the web address is wrong even when your eyes do not.
With the servers now in police hands, investigators say they will comb through the seized machines for records of who bought subscriptions. In other words, the 1,800 customers may not be anonymous for much longer.
Kratos itself is done. The business model, sadly, is not. Another kit will fill the gap within weeks. It always does.



