HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Police Dismantle Kratos Phishing-as-a-Service Platform Behind 15,000 Monthly Campaigns

German and U.S. authorities seized the Kratos phishing‑as‑a‑service infrastructure, which powered ~15,000 credential‑stealing campaigns per month across 35 countries. The takedown illustrates why continuous security‑awareness training and SOC 2 evidence of control effectiveness are critical for audit readiness.

LiveThreat™ Intelligence · 📅 July 22, 2026· 📰 helpnetsecurity.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
5 sector(s)
Actions
3 recommended
📰
Source
helpnetsecurity.com

Police Dismantle Kratos Phishing-as-a-Service Platform Behind 15,000 Monthly Campaigns

What Happened — German and U.S. law‑enforcement agencies seized 200 servers and arrested the alleged operator of the Kratos phishing‑as‑a‑service (PhaaS) platform. The service had been used by an estimated 1,800 “franchisees” to launch roughly 15,000 credential‑stealing campaigns each month, affecting victims in 35 countries.

Why It Matters for Compliance & Audit Readiness

  • Phishing remains a top vector for compromising login credentials, directly testing the effectiveness of SOC 2 Access Control (CC6.1) and Security Awareness Training requirements.
  • Continuous evidence of employee training, phishing‑simulation results, and incident‑response playbooks is essential to demonstrate due diligence during a SOC 2 audit.
  • The takedown underscores the need for real‑time monitoring of credential‑theft attempts as audit evidence of a mature security program. Capability: Security Awareness Training.

Who Is Affected — Enterprises across finance, healthcare, technology, and retail sectors; any organization with Microsoft‑based email or cloud services.

Recommended Actions

  • Review and update your phishing‑simulation program to cover Microsoft‑themed lures similar to those used by Kratos.
  • Map the simulation results to SOC 2 CC6.1 (Access Control) and CC7.1 (Security Awareness) controls, collecting evidence for audit readiness.
  • Verify that incident‑response procedures include rapid credential rotation and multi‑factor enforcement when phishing is suspected.

Technical Notes — The platform operated a subscription model (≈ €300 k revenue since 2024) and accepted cryptocurrency payments via a Telegram shop. Campaigns leveraged cloned Microsoft login pages to harvest passwords and email addresses. Source: Help Net Security

📰 Original Source
https://www.helpnetsecurity.com/2026/07/22/bka-fbi-kratos-phishing-platform-takedown/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Awareness is a control you can evidence too.

Verisq AI Trust Operations records training completion and policy adoption as audit evidence — turning 'we train our staff' into something you can actually prove.

See how Verisq AI Trust Operations covers awareness →