The disruption of Kratos may have removed one criminal service, but the deeper problem is the reusable playbook behind modern Microsoft 365 account-takeover campaigns.
A cross-border operation against Kratos did more than knock out infrastructure - it highlighted how phishing-as-a-service turns credential theft into a rented criminal utility.
Germany, the U.S., and Indonesian authorities moved against the Kratos phishing platform, a reminder that modern credential theft often depends on rented infrastructure, not lone operators.
A subscription phishing kit is using familiar cloud-sharing patterns and bot checks to steer Microsoft 365 users toward fake sign-in pages.
A Telegram-linked phishing service shows how identity theft now borrows the mechanics of SaaS, combining device-code abuse, token persistence, and AI-written lures.
A late-June phishing run against Microsoft 365 shows how attackers are industrializing a legitimate sign-in method, turning trusted authentication into a reusable identity-abuse chain.
A newer Kratos PhaaS flow is drawing attention because it appears designed to look more like routine sign-in friction while reducing the cues defenders normally use to triage phishing.
A fast-moving phishing kit is being watched as it shifts from early testing to live deployment, with Microsoft sign-ins in its sights and proxy-style attacks at the center of the risk.
An INTERPOL-led operation disrupted Sniper Dz, a phishing-as-a-service platform, and the case shows how modern phishing is built like infrastructure, not just spam.
Campaigns tied to a SniperDz label show how brand spoofing, social lures, and browser-level tricks can turn everyday browsing into a repeatable fraud pipeline.