Dateline: July 23, 2026
200 Servers Seized, One Arrest, and a Customer List Worth Gold
Somewhere in Indonesia on Monday, police knocked on a door and arrested a man who had never sent a phishing email in his life. He just built the tool that let 1,800 other people send them. Now his servers are dark, his domain belongs to the FBI, and a lot of security teams are wondering what actually changed.
What Happened?
German prosecutors in Frankfurt and the Federal Criminal Police Office announced on July 20 that they had dismantled Kratos, a phishing platform sold like software. They called the operation Olympus Blade. The FBI’s Dallas field office and the US Attorney for the Northern District of Texas worked the American side. Indonesian police made the arrest.
More than 200 servers went offline. A seizure banner now sits on the group’s website, and the domain has been transferred to the FBI.
Kratos was not a gang that broke into companies. It was a vendor. Customers paid in cryptocurrency, logged into a dashboard, and deployed a fake Microsoft 365 login page with a few clicks. The panel let them pick an anti bot system, set geographic filters, install SSL certificates, and route stolen data to a Telegram bot.
German investigators say more than 1,800 people bought access and used it to run about 15,000 phishing campaigns every month. Confirmed victims turned up in 35 countries, mostly across Europe and the US. The operator pulled in at least 300,000 euros in subscription fees since 2024.
The pages did more than steal passwords. They grabbed session cookies too, which is how attackers walked past multi factor authentication and took over accounts outright.
What’s the Impact?
Here is the part that should worry you. The takedown removed a supplier, not the criminals.
Frank Dickson at IDC put it plainly. Seizing servers and arresting one developer removes infrastructure, not intellectual property. Phishing kits get cloned, forked, and resold constantly, and those 1,800 customers did not disappear. They lost a vendor in a market where vendors get replaced fast.
Noah Kenney at Digital 520 went further. The people running the attacks were never part of the organization. They still have their target lists, their sending infrastructure, and whatever access they already established. The tooling went dark. The attackers did not.
Even the naming is a mess. Microsoft tracks this kit as SneakyLog and dates it to early 2025. KnowBe4 says Kratos first showed up in January 2026 and grew out of an older line of trojans, with no SneakyLog connection at all. When researchers cannot agree on what to call something, it usually means the thing gets renamed and resold on a regular schedule.
What the seized servers might give investigators is a customer list. Dickson called that the real prize.
How to Avoid This
Stolen credentials are only the opening move. A single compromised Microsoft 365 account becomes invoice fraud, supplier scams, and phishing sent from a trusted mailbox.
- Treat session theft differently from password theft. If a login page acted as a proxy or relayed cookies, resetting the password fixes nothing. Revoke active sessions and refresh tokens.
- Watch for the lures that actually work. Shared document notices, DocuSign requests, and invoice alerts delivered through real SharePoint, OneDrive, Canva, or Microsoft Forms links.
- Attackers use legitimate services as the first hop because email gateways trust them. In 114 sandbox sessions studied by ANY.RUN, the phishing mail had already cleared corporate filters.
- Move to phishing resistant MFA. Passkeys and hardware security keys do not hand over a replayable cookie the way push notifications and codes do.
- Hunt backward through your logs. The IOC list attached to this post gives you file hashes, exfiltration endpoints, and domains to search against the last six months.