Police Seized Kratos Phishing Infrastructure in July

The international operation dismantled a platform designed to bypass Microsoft 365 multi-factor authentication.

Updated on Sept. 27, 2026 in Cybersecurity

Bold flat-color editorial illustration in navy, cream, and deep red, showing an orderly monolithic server rack representing digital infrastructure disruption.
Law enforcement agencies from the U.S., Germany, and Indonesia have dismantled the Kratos phishing-as-a-service infrastructure used to bypass Microsoft 365 security protections. AI Illustration. Upload story photo >

Live Poll

Do you trust current multi-factor authentication tools to keep your personal online accounts secure?

On July 27, 2026, German and United States law enforcement agencies announced the seizure of the Kratos phishing-as-a-service infrastructure. Simultaneously, Indonesian authorities arrested the alleged developer and operator of the malicious kit.

Why it matters

The takedown disrupts a tool specifically built to commoditize credential theft against Microsoft 365, a service critical to global business and government operations. By arresting the operator, authorities targeted the supply chain for lower-skilled cybercriminals.

The Kratos kit operates by intercepting session data in real-time, allowing attackers to hijack active Microsoft 365 sessions. This technique bypasses multi-factor authentication (MFA) protocols by capturing the authenticated session token instead of requiring a one-time code.

The players

Frankfurt public prosecutor cybercrime unit

A German regional authority focused on investigating and prosecuting digital criminal activities.

German Federal Criminal Police Office

The central agency responsible for national criminal investigations and international police cooperation in Germany.

Microsoft

A multinational technology corporation providing the cloud infrastructure and 365 productivity suite targeted by the Kratos kit.

The details

The platform functioned as a phishing-as-a-service kit, providing low-barrier access for criminals to target Microsoft 365 login sessions. It utilizes an interception mechanism to capture authentication data during the login flow, effectively neutralizing the security provided by multi-factor authentication. By moving the point of attack to the session token, the kit allows unauthorized access to systems even if the target organization has standard security protections enabled.

Timeline

  1. July 27, 2026: Law enforcement seized the Kratos infrastructure and announced the operation.

The Tech Race

This action follows the operational pattern established by the 2023 takedown of the Genesis Market, where law enforcement began systematically dismantling the backend infrastructure of phishing syndicates. It marks a shift from reacting to individual scams toward disrupting the service providers that sell cybercrime tools as a commodity.

Organizations should continue to monitor for anomalous session activity, as the underlying capability to intercept tokens remains a threat from other kits. IT administrators should verify that conditional access policies are configured to minimize session token longevity.

The takeaway

The Kratos case illustrates how international coordination can successfully disrupt the commodification of complex cyberattacks. Stakeholders should track future indictments related to the arrested developer to determine if authorities possess enough evidence to permanently dismantle the kit's remaining ecosystem.

Further reading

For more on how authorities are dismantling cybercriminal operations, see the latest updates in Cybersecurity.

Source note: This article includes information reported by Computer Crime Research Center.

Live Poll

Do you trust current multi-factor authentication tools to keep your personal online accounts secure?

Police Seized Kratos Phishing Infrastructure in July