IAMRoadmapIAMRoadmap
INDUSTRY TRENDS

IAM News: Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA

German and US law enforcement have taken down the core infrastructure of Kratos, described by German investigators as one of the world's most widely used crimin

2 min readJuly 22, 2026IAM Roadmap Team

Key Insight

German and US law enforcement have taken down the core infrastructure of Kratos, described by German investigators as one of the world's most widely u...

📰 Source: The Hacker News

Summary

German and US law enforcement, along with Indonesian authorities, have dismantled the core infrastructure of Kratos, a widely used phishing kit that targeted Microsoft 365 sessions and bypassed Multi-Factor Authentication (MFA). The takedown marks a significant victory in combating cybercrime, but IAM professionals should remain vigilant as phishing kits continue to evolve. The arrest of the individual behind Kratos highlights the importance of international cooperation in tackling cyber threats.

Attack Flow

Delivered

Clicks Link

Exploits Vulnerability

Bypasses MFA

Phishing Email

Target User

Kratos Phishing Kit

Microsoft 365 Session

Unauthorized Access

IAM Impact

The takedown of Kratos highlights the ongoing threat of phishing kits to identity and access management (IAM) systems. As attackers continue to evolve their tactics, IAM professionals must stay ahead of the curve by implementing robust security measures, such as:

  • Implementing robust MFA protocols that are resistant to bypass
  • Conducting regular security awareness training for users
  • Monitoring and analyzing user behavior to detect potential threats

Key Takeaways

  • Phishing kits like Kratos continue to pose a significant threat to IAM systems, highlighting the need for robust security measures
  • International cooperation is crucial in tackling cybercrime, as seen in the takedown of Kratos
  • IAM professionals must stay vigilant and adapt to evolving threats to ensure the security of their systems

Recommendations

  • Organizations should implement robust MFA protocols that are resistant to bypass and regularly review their MFA policies
  • IAM professionals should prioritize security awareness training for users, focusing on identifying and reporting suspicious emails
  • Organizations should monitor and analyze user behavior to detect potential threats and implement incident response plans to mitigate the impact of a phishing attack
Trend Topics
IAM newssecurity newsThe Hacker News
All Articles