Shutting down Kratos is only the first step. When authorities seize the platform’s central infrastructure, they may also recover the subscriber data and campaign material that show who used it and how they ran phishing operations. Germany and U.S. authorities dismantled Kratos’ core infrastructure and arrested its developer in Indonesia. Kratos was a phishing-as-a-service platform with global reach, so the seizure is more than a single disruption. The bigger risk for the ecosystem is follow-on exposure. If investigators can tie subscribers to templates and infrastructure, one takedown can turn into multiple cases against related phishing crews and customers.
Part of the PlainSec briefing for 2026-07-22