US, German, Indonesian forces dismantle Kratos phishing-as-a-service platform
Operation “Olympus Blade” saw law‑enforcement agencies from the United States, Germany and Indonesia cooperate to dismantle Kratos, a phishing‑as‑a‑service platform that specialized in stealing Microsoft 365 credentials and bypassing two‑factor authentication. The joint effort neutralised more than 200 servers and led to the arrest of the platform’s presumed developer in Indonesia.
Kratos offered a subscription model used by roughly 1,800 criminal affiliates, enabling about 15,000 phishing campaigns per month. The service generated credential theft affecting hundreds of thousands of victims in over 30 countries, with a concentration in Europe and North America. The takedown represents a significant blow to a large‑scale cyber‑crime business model and sends a clear signal to similar illicit operations.