Back to the desk

News briefing

German police dismantle Kratos phishing kit used to hijack Microsoft 365 sessions

Severity: HighEMEALaw enforcement2026-0720-KR03 min readBy Vivek Kumar
Conceptual illustration: a shattered fishing hook beside an abstract login screen. Text: PHISHING KIT TAKEDOWN.

AI-generated editorial illustration by CyberShitty. Not a photograph or a document from the organisations named.

The BKA and Frankfurt's ZIT cybercrime prosecutors, working with US partners, took more than 200 Kratos servers offline. Indonesian authorities arrested the kit's alleged developer and administrator.

01 / What happened

Germany's Federal Criminal Police Office (BKA) and the Frankfurt am Main Public Prosecutor General's Office, through its Central Office for Combating Internet Crime (ZIT), announced on 20 July 2026 that they had shut down Kratos, a phishing-as-a-service platform, in cooperation with US law enforcement. According to the BKA, more than 200 servers belonging to the Kratos infrastructure were rendered unusable.

The person described as the platform's developer and technical administrator was arrested in Indonesia by local authorities, the BKA said. The suspect has not been publicly named. The Hacker News reported the takedown on 22 July.

Microsoft Threat Intelligence tracks the same kit as SneakyLog. In a March 2026 blog post, Microsoft said the service had been available since at least early 2025 and described a 10 February 2026 campaign in which roughly 100 organisations, mostly in US manufacturing, retail and healthcare, received tax-themed emails carrying personalised QR codes that led to fake Microsoft 365 sign-in pages.

02 / Why it matters

Kratos sold ready-made fake Microsoft login pages to other criminals, letting less skilled operators run campaigns at scale. The BKA estimates that more than 1,800 criminal "franchisees" bought access and ran around 15,000 phishing campaigns per month, and that the operators earned over EUR 300,000 since 2024.

Research by ANY.RUN, cited by The Hacker News, found customers could choose between a simple credential-harvesting page and a reverse-proxy mode that relays the victim's login to Microsoft in real time. That adversary-in-the-middle (AiTM) approach captures the resulting session cookie, which can let an attacker reuse an authenticated session even when the victim completed a standard multi-factor prompt.

Session-stealing kits turn one-time MFA codes into a speed bump rather than a barrier.

BKA cybercrime head Carsten Meywirth was quoted by The Hacker News as saying the case showed that even highly professional phishing infrastructure can be tackled effectively.

03 / Who is exposed

The BKA identified victims mainly in Europe and the United States. Organisations most at risk from this style of attack include:

  • Microsoft 365 tenants relying on SMS, app-push or one-time-code MFA rather than phishing-resistant methods.
  • Users targeted with QR-code lures, which move the login onto a phone and outside some email and web filters.
  • Accounts whose sessions may have been captured before the takedown; stolen cookies can remain valid after infrastructure goes offline.

04 / Confirmed vs. claimed

Confirmed by the BKA: the joint German-US action, more than 200 servers disabled, the arrest in Indonesia of the developer and administrator, and estimates of about 850 identified victims in 35 countries, over 1,800 franchisees, around 15,000 campaigns a month and more than EUR 300,000 in earnings. Reported but not matched in the BKA release: The Hacker News says authorities put victim numbers in the hundreds of thousands across more than 30 countries. This desk could not reconcile the two figures and uses the BKA's count. Charges and the suspect's identity have not been disclosed.

05 / What to do now

  • Move privileged and high-risk Microsoft 365 users to phishing-resistant MFA such as FIDO2 security keys or passkeys.
  • Use Conditional Access policies that bind sessions to compliant or managed devices, reducing the value of stolen cookies.
  • Review sign-in logs for sessions reused from unfamiliar IP addresses or locations, and revoke refresh tokens for affected accounts.
  • Treat unexpected tax or HR documents containing QR codes as suspicious, and brief staff on QR-based phishing.
  • Follow Microsoft's published guidance on Safe Links, SmartScreen and network protection against known phishing domains.

Source log / 2026-0720-KR

More from the archive