🟡 Medium  |  Source: The Register — Security


The Kratos phishing-as-a-service (PhaaS) platform has been dismantled by an international law enforcement operation led by German authorities, with over 200 servers taken offline. The alleged developer has been arrested in Indonesia. Kratos was a commercial kit that allowed criminals to conduct large-scale phishing campaigns without technical expertise, lowering the barrier to credential theft significantly.

Security Architect’s Take: Review your organisation’s email security telemetry and SIEM logs for indicators of compromise associated with Kratos-generated phishing infrastructure; cross-reference against published IOCs from the takedown. This is also a timely prompt to validate that phishing-resistant MFA (e.g. FIDO2/passkeys) is enforced across all identity providers, reducing the value of any credentials harvested via PhaaS platforms.

Original advisory: Kratos phishing-as-a-service kit loses its battle with international law enforcement