Germany’s Federal Criminal Police Office, working with the Frankfurt am Main Public Prosecutor’s Office and United States law enforcement, shut down one of the world’s largest phishing-as-a-service operations on July 20, 2026. Authorities took down more than 200 servers linked to a criminal platform called Kratos, which was built specifically to power scam attacks worldwide. Indonesian police arrested the platform’s developer and technical administrator on the same day. The operation affected roughly 850 identified victims across 35 countries, most concentrated in Europe and the United States, marking one of the biggest strikes against organized cybercrime this year.
What Investigators Found
Kratos functioned as a digital toolkit that let criminals build convincing fake Microsoft login pages designed purely to deceive users. These pages were built to trick victims into entering usernames, passwords, and email credentials on what looked like a legitimate authentication screen once stolen through phishing; that data opened the door to further crimes, including account takeovers, identity theft, and financial fraud against ordinary internet users.
A Phishing Business Built For Scale
What made Kratos particularly dangerous was its business model. The developer did not run scam campaigns directly. Instead, the toolkit was rented out to other cybercriminals, a setup investigators describe as phishing-as-a-service. This let people with little technical skill launch professional-looking credential-theft attacks without writing a single line of code themselves.
German authorities say the operation generated more than 300,000 euros since 2024. Investigators estimate that over 1,800 criminal affiliates purchased access to Kratos and ran an estimated 15,000 fraudulent campaigns every month. Each campaign had the potential to reach thousands of recipients worldwide, which is part of why this criminal network grew so quickly and attracted international attention.

The Scale Of The Damage
Investigators say the nearly 850 confirmed victims likely represent only a fraction of those actually targeted, since campaigns of this size typically touch far more people than official victim counts capture. The 35 affected countries span multiple continents, showing how a single credential-theft toolkit sold from one location can generate harm on a truly global scale.
Read more: Microsoft Update Blocked
How The Takedown Happened
The joint operation combined a physical arrest with a technical shutdown of the underlying infrastructure. Indonesian police detained the administrator behind Kratos, while German and American investigators worked to turn off the servers powering the toolkit. Together, these actions knocked out more than 200 servers that hosted fake login pages and supporting tools.
Because the administrator built and maintained the core system personally, removing that single point of control appears to have damaged the entire network. Officials confirmed that phishing campaigns relying on Kratos can no longer continue, since the underlying infrastructure has been fully dismantled and seized by law enforcement.
Why This Phishing Case Matters
Phishing remains one of the most common ways criminals steal personal data, and services like Kratos significantly lower the barrier to entry. A scam kit that mimics a trusted brand such as Microsoft can fool even cautious users, especially when the fake page looks nearly identical to the real one.
Law enforcement officials called this one of the most significant strikes against a credential-theft-as-a-service group to date. By removing both the technical infrastructure and the person who built it, investigators say they prevented further crimes and protected many potential victims from having their credentials stolen or misused.
Read more: Phishing Attacks

What This Means For Everyday Users
Attacks built on kits like Kratos typically rely on urgency and familiarity to work. Victims are often pushed toward a login page that looks exactly like a service they already trust, then asked to confirm their account details right away, without time to think it through.
A few habits reduce exposure to this kind of scam attempt.
- Check the web address carefully before entering login credentials, since fake pages often use slightly altered domains.
- Enable multi-factor authentication wherever available, since a stolen password alone is less useful to attackers when a second verification step exists.
- Avoid clicking login links inside unsolicited emails or texts, and type the website address directly into the browser instead.
- Report suspicious emails claiming to be from Microsoft or similar services to the platform’s official abuse channels.
These simple steps make it much harder for scam pages to succeed, even when they are built using sophisticated criminal toolkits designed to look convincing.
Ongoing Investigation
Authorities have not ruled out further arrests connected to the Kratos network, since the case involves criminal affiliates spread across dozens of countries. Investigators are continuing to analyze seized servers to identify additional individuals who purchased access to the toolkit and used it against victims. German officials indicate that data recovered from the seized infrastructure could support new prosecutions in the coming months, as the full scope of the affiliate network becomes clearer to law enforcement teams working across multiple continents.













