Law enforcement agencies in Germany and the United States have dismantled the Kratos phishing-as-a-service (PhaaS) platform and arrested its developer in Indonesia. The operation, dubbed "Operation Olympus Blade," involved the seizure of over 200 servers, effectively rendering the malicious service inoperable.
The Frankfurt Prosecutor General's Office (ZIT) and Germany's Federal Police (BKA) led the international effort, collaborating with U.S. law enforcement. The BKA characterized Kratos as one of the most widely used criminal phishing services globally, with confirmed victims across 35 countries, particularly within Europe and the United States.
Authorities estimate that more than 1,800 criminal customers purchased access to Kratos, using it to launch approximately 15,000 phishing campaigns each month. These campaigns had the potential to affect thousands of recipients worldwide. The phishing toolkit allowed threat actors to create and manage convincing fake Microsoft authentication pages designed to steal email addresses and passwords.
Once compromised, these Microsoft accounts were frequently leveraged for further criminal activities, including business email compromise (BEC), data theft, account takeover, and additional phishing attacks targeting the victims' contacts.
The service's owner is believed to have generated at least 300,000 Euros (approximately $342,000 USD) in subscription fees since 2024. With the arrest of the technical administrator and the shutdown of critical infrastructure, authorities anticipate a halt to these ongoing phishing campaigns.
A seizure banner has been placed on the service's website, announcing the law enforcement action and indicating that domain ownership has been transferred to the FBI. The seized servers are expected to provide new forensic evidence, which may aid in identifying additional customers of the Kratos service.






