Kratos phishing platform seized. M365 exposure is not.
German BKA and US authorities dismantled Kratos PhaaS and arrested its developer in Indonesia. Passkey rollout still matters more than the takedown headline.
Confirmed reporting by BleepingComputer, 2026-07-21. Frankfurt’s Prosecutor General Office (ZIT) and Germany’s Federal Criminal Police (BKA), working with US law enforcement, seized the infrastructure behind Kratos on Tuesday — more than 200 servers dark, roughly 1,800 paying customers cut off, and the developer arrested in Indonesia. The BKA called Kratos “one of the world’s most widely used criminal phishing services.” The operation is named Olympus Blade.
Good work. And the honest read: your Microsoft 365 exposure is unchanged today unless you’d already deployed phishing-resistant MFA.
What changed
Per BleepingComputer’s write-up of the BKA statement:
- Model: subscription rental, targeting Microsoft account credentials with fraudulent M365 login pages.
- Volume: approximately 15,000 phishing campaigns per month at peak.
- Reach: confirmed victims in 35 countries, concentrated in Europe and the US.
- Revenue: at least €300,000 since 2024.
- Post-compromise: BEC, account takeover, data theft, and further phishing pivoting through the compromised user’s contacts.
The seizure took the platform offline. It did not repossess the tradecraft. Session-token replay, fraudulent M365 landing pages, and AiTM against push/SMS second factors are commodity now, not one dev’s proprietary edge. We’ve seen the same pattern before — Forg365 got the same kind of headline a week ago. Take one PhaaS down, the next one gets a subscription bump. That’s the honest timeline.
What to actually do this week
- Audit which of your users still authenticate to M365 with password plus push or SMS. If any privileged account still can, that is the fix. Passkeys or FIDO2 security keys — everything else is theater against a competent AiTM kit like the one BKA just seized.
- Turn on Entra Conditional Access token protection (Microsoft Learn) for sign-in sessions where it’s supported. Kratos-class kits replay the stolen session cookie, not the password. Token binding raises the cost of that replay.
- Kill legacy authentication. Basic auth, IMAP, POP, SMTP AUTH, ActiveSync where you don’t need it. Kratos-adjacent kits still ride these paths because push MFA doesn’t apply to them.
- Pull the last 60 days of
SignInLogsfor token reuse across geographies inside a short window. That is the tell for a lifted session cookie, not the password-reset alerts your users ignored. - For your top 5% of accounts — finance, exec staff, whoever holds DNS or your identity tenant — pair phishing-resistant MFA with device compliance signals (Entra + Intune, Okta FastPass, Google BeyondCorp Enterprise). That’s the smallest population where the effort is unambiguously worth it.
What isn’t the fix
- Blocking the domains Kratos used. The seizure already did that. The next kit will rotate infrastructure the same way.
- Buying another phishing-training platform. Users clicked because the login page looked correct. Training doesn’t scale against 15,000 campaigns a month. Passkeys do.
- Waiting for the next indictment. There are more PhaaS operators than takedowns.
Priority call
If your M365 tenant is still password-first, the kit brand behind the phish doesn’t matter — the exposure lives in your identity stack, not on the servers the BKA just carted off. Prioritize in this order:
- Tonight: pull sign-in logs, disable legacy auth on any tenant that still has it.
- This week: enable token protection in Conditional Access, verify passkey enrollment paths work end-to-end.
- This quarter: passkeys mandatory for every privileged account.
Operation Olympus Blade cost 1,800 criminals their platform, and every server the BKA carted off is a keyset that won’t be resigning tomorrow’s phishing certs. Take the win. Don’t confuse it with a defense.
Found this useful? Share it.


