Law enforcement took down Kratos. But the 1,800 criminal subscribers who paid for that phishing-as-a-service platform still have the kit code, and security researchers confirm they are already adapting it. For Canadian finance teams and executives, the practical question is not whether criminals will continue using these techniques; it is whether your organization is ready when they do.
How a $350 Monthly Subscription Bypassed MFA
Kratos was a phishing-as-a-service (PhaaS) platform dismantled by Germany’s Federal Criminal Office (BKA) and the FBI in July 2026 as part of Operation Olympus Blade. Before its shutdown, Kratos powered roughly 15,000 phishing campaigns per month across more than 30 countries, with approximately 1,800 criminal subscribers paying between $120 and $350 per month for access.
What set Kratos apart was its use of adversary-in-the-middle (AiTM) techniques. Rather than directing victims to a simple fake login page, Kratos relayed real authentication attempts in real time to Microsoft’s legitimate servers, capturing the session token issued after a successful MFA challenge. An employee who completed every authentication prompt correctly could still lose their session. Standard multi-factor authentication did not stop it.
This attack method feeds directly into business email compromise. The FBI’s 2025 Internet Crime Complaint Center report logged 24,768 BEC complaints, totalling $3.05 billion in reported losses, a 16 percent increase from 2024. Microsoft 365 session access is the most common first step in BEC fraud. For organizations that have not yet mapped their exposure to AiTM-style attacks, understanding where your organization actually stands before attackers probe your Microsoft 365 environment is the most consequential first move.
The Takedown Did Not Erase the Threat
When a PhaaS platform is dismantled, its techniques rarely disappear with it. Kratos ran on disposable domains and compromised WordPress hosting, infrastructure that resurfaces quickly under new names. Security researchers have already documented copycat campaigns using Kratos-style AiTM kits against Microsoft 365 users in the weeks since Operation Olympus Blade. The 1,800 former subscribers still hold working copies of the kit code, which means the threat level for organizations has not materially changed.
Keeping employee readiness ahead of evolving techniques requires exercises that reflect current attack methods, not the credential-harvest pages of two years ago. AiTM-style attacks look and feel different from commodity phishing, and employees who have never encountered them are not prepared to flag them.
The Canadian Dimension
The Canadian Centre for Cyber Security documented more than 100 AiTM phishing campaigns specifically targeting Canadian Microsoft Entra tenants between 2023 and early 2025, in advisory ITSM.30.031. Many of those campaigns culminated in payroll diversion: attackers who captured a session token logged into the victim’s payroll or HR platform and rerouted salary deposits. This is a category of business email compromise that leaves employees without pay and organizations scrambling to recover funds that may never come back.
The Training Gap That Makes This Work
In our work with Canadian finance and executive teams, we consistently see that the highest-value targets receive the least training, because nobody wants to make the CEO sit through a 20-minute module. This is exactly the gap that incidents like the one above exploit.
The exposure here is behavioural, not just technical. Session theft succeeds because employees do not have a habit of pausing when an authentication request feels slightly off, and organizations have not built a clear channel for reporting unusual login prompts or unexpected IT helpdesk calls. Reporting speed is often the only control that works once a session token is in the wrong hands.
A concrete step this week: review whether your finance and executive teams have received dedicated training on AiTM-style attacks and unusual authentication requests, separate from your general employee population. Building a security awareness program that reaches the people with payment authority is not optional when BEC losses are measured in billions.
Sources
- Police dismantle Kratos phishing platform behind 15,000 monthly campaigns — Help Net Security, July 22, 2026
- Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA — The Hacker News, July 2026
- Dismantled Kratos Phishing-as-a-Service Kit Fuels Copycat Microsoft 365 Campaigns — Cyberpress, July 2026
- FBI Internet Crime Complaint Center 2025 Annual Report — FBI IC3, 2025
- Advisory ITSM.30.031 on AiTM Phishing Against Canadian Entra Tenants — Canadian Centre for Cyber Security