Back to News
Cybersecurity

Global Law Enforcement Unravels Kratos Phishing Kit Targeting Microsoft 365 Users

Authorities dismantle a major phishing operation aimed at stealing Microsoft 365 credentials, highlighting the ongoing threat of cybercrime.

In a significant blow to cybercriminal activity, law enforcement agencies from Germany and the U.S. have successfully dismantled the Kratos phishing kit, a sophisticated tool reportedly used to compromise Microsoft 365 sessions and bypass multi-factor authentication (MFA). The operation, led by Germany's Federal Criminal Police Office (BKA) and the Frankfurt public prosecutor's cybercrime unit (ZIT), resulted in the arrest of the suspected developer in Indonesia, marking a critical step in combating phishing threats that exploit widely used platforms.

For businesses, this development underscores the persistent vulnerabilities associated with cloud-based services and the importance of robust cybersecurity measures. The dismantling of the Kratos kit serves as a reminder that even with MFA in place, organizations must remain vigilant and adopt comprehensive security protocols to mitigate such threats. As cybercriminals continuously evolve their tactics, companies must prioritize employee training and implement advanced security solutions to defend against phishing attacks. This incident not only highlights the collaborative efforts of international law enforcement in addressing cybercrime but also stresses the need for ongoing vigilance in the cybersecurity landscape.

---

*Originally reported by [The Hacker News](https://thehackernews.com/2026/07/police-dismantle-kratos-phishing-kit.html)*