Wire · founder news, decoded · regulatory
Kratos phishing-as-a-service kit loses its battle with international law enforcement
◆ Published
21 July 2026
◆ Topic
regulatory
◆ Sectors
◆ Geography
◆ Source
◆ Verified
Fusion42 · 21 July 2026 · Fusion42 review
German authorities dismantled Kratos, a widespread phishing-as-a-service kit that enabled low-skill criminals to harvest credentials and bypass MFA using fake Microsoft pages, arresting its alleged developer in Indonesia after neutralising over 200 servers. The platform was used by approximately 1,800 criminal enterprises to launch around 15,000 phishing campaigns per month targeting hundreds of thousands of victims across 30+ countries.
This Wire brief sits within Fusion42's coverage of Fintech. Wire is Fusion42's founder-focused intelligence feed: each story is connected to the funds and startups it names — every one with a live profile on Raise or Scout — so founders can follow the capital and the momentum behind the headline rather than just the headline itself. Wire analysis is one of the live surfaces Arthur reasons over.
◆ The Wire takeaway
If you sell identity verification, passwordless authentication, or MFA to finance or healthcare, your competitive moat just shrank—Kratos proved that MFA bypass at scale is a solvable problem for criminals. The takedown removes one platform, but 1,800 customers will now shop elsewhere: your next deal will hinge on whether you solve account takeover better than whatever replaces it.
◆ Related on Wire
- Lumma Stealer Survives 2 Takedowns, Hits 394K PCs [2026]19 July 2026
- North Korea-Linked Contractor Had MetaMask Code Access for Over a Month19 July 2026
- Korea's FSS and KORFIN form taskforce to curb online fraudulent payments15 July 2026
- Feds escalate hospital hacker crackdown: 11 cases17 July 2026
- Dutch court declares crypto platform Knaken bankrupt over mi|Cointelegraph17 July 2026
- North Korean hackers stole two-thirds of crypto in 2026: report8 July 2026
◆ Topics
Fintech · phishing-infrastructure · mfa-bypass · credential-theft · international-enforcement · microsoft-365-targeting