German Police Shut Down Kratos Phishing Network, But Experts Say the Pause Will Be Brief
Authorities seized more than 200 servers and arrested a developer in Indonesia. Security researchers say the 1,800 customers who used the service are already shopping for a replacement.

Key points
- German law enforcement, working with US and Indonesian agencies, seized more than 200 servers belonging to Kratos in mid-2025 and arrested one unnamed developer in Indonesia.
- Kratos was a phishing-as-a-service platform, meaning it sold ready-made criminal tools to approximately 1,800 paying customers who ran their own phishing campaigns.
- The platform specialized in stealing Microsoft 365 session tokens and bypassing MFA (multi-factor authentication, the extra login step that asks for a code after your password) using adversary-in-the-middle proxies, which are fake login pages that sit invisibly between a victim and a real website.
- Security researchers broadly agree the takedown is a real disruption but not a lasting one, because the underlying criminal demand and competing services remain intact.
- The seized customer list is considered the most valuable intelligence asset from the operation.
German police announced this week that they had "completely disabled" the infrastructure of Kratos, one of the largest phishing-as-a-service operations on record. Phishing-as-a-service works like a subscription software business, except the product is a toolkit for running fake-email scams. Criminals pay a fee, get access to polished tools, and go phishing. Kratos had around 1,800 paying customers doing exactly that.
One developer and technical administrator was arrested in Indonesia. Over 200 servers were seized. German authorities declared the platform dead.
Experts are less certain.
Should businesses expect phishing attacks to drop?
No, at least not for long. The people who bought Kratos tools still have everything else they need: target lists, sending infrastructure, and any access they already gained before the shutdown. The toolkit went dark. The criminals did not.
"The 1,800 customers who bought it still have their target lists, their sending infrastructure and whatever access they had already established," said Noah Kenney, principal consultant at Digital 520. "The tooling went dark, but the people phishing your employees last week are still working, shopping for a replacement that already exists."
Frank Dickson, group VP for security at IDC, put it plainly: "For every roach that you squish, there are a hundred that you do not see."
Kratos built its reputation on one particularly dangerous trick. Its tools created convincing fake Microsoft 365 login pages, the kind office workers see every day. When a victim typed in their password, Kratos did not just steal the password. It stole the session token, a small file a browser holds after a successful login that proves you already passed the security checks. With that token, criminals can walk straight past MFA without ever knowing the password at all. Dickson called this "the exact technique behind a lot of the business email compromise activity of the past two years."
Assaf Morag, a researcher at Flare, called the crackdown "symbolic." Pieter Arntz at Malwarebytes was more generous, saying it is "a meaningful disruption" to many downstream customers at once, but added that "a rebrand or partial re-emergence is plausible, which is the historical pattern for PhaaS operations."
The one piece security researchers genuinely want to see used: the customer list pulled from those seized servers. As Dickson said, first reported in more detail by CSO Online, "That, my friend, is gold."
What affected organisations should do
Kratos is down, but the techniques it sold are not. Review whether your Microsoft 365 environment uses phishing-resistant login methods such as hardware security keys or passkeys, which are far harder to defeat with fake login pages. Audit recent login activity for unusual session behaviour, such as logins from new locations shortly after a user clicks a link. And remind staff that a login page that looks exactly right is not proof it is real.



