Cybercrime, Platform

Cybercrime Platform With 1,800 Users Dismantled as Mobile Attacks Hit Record Levels

Published on 07/23/2026 at 07:43 | Redaktion boerse-global.de

German police and international partners shut down the Kratos Phishing-as-a-Service platform, seizing 200+ servers and arresting 13 suspects amid a surge in mobile malware and ransomware attacks.

Kratos Phishing Service Dismantled: 200 Servers Seized, 12 Arrested
Cybercrime Platform With 1,800 Users Dismantled as Mobile Attacks Hit Record Levels Illustration mit AI erstellt übermittelt durch boerse-global.de

German authorities, working alongside international law enforcement, have taken down a phishing service called “Kratos” that allowed roughly 1,800 subscribers to launch up to 15,000 criminal campaigns each month. The takedown marks one of the larger disruptions of a so-called “Phishing-as-a-Service” operation in recent years.

The Federal Criminal Police Office (BKA) and its partners seized more than 200 servers during the operation. In Indonesia, investigators arrested one developer; in Pakistan, twelve additional suspects were taken into custody. Officials also recovered approximately 96,000 manipulated banking applications. The infrastructure specifically targeted customers of Commerzbank, Deutsche Bank and Postbank. Since 2024, the operators are believed to have stolen around 300,000 euros.

The dismantling comes at a time when cyberattacks on mobile devices are surging. During the first quarter of 2026, security researchers blocked roughly 2.67 million malware attacks targeting smartphones worldwide. Over 306,000 new malicious programs were identified in that period alone.

Ransomware and Vulnerabilities Spike

The threat landscape has expanded dramatically in the first half of the year. Experts recorded more than 37,000 new security vulnerabilities — a 51 percent increase compared to the same period last year. More than half of these flaws are classified as highly dangerous or critical.

Ransomware cases have also exploded, with 4,544 incidents logged — a 25 percent rise. That equates to roughly 25 attacks per day.

Artificial intelligence is driving much of this escalation. According to a recent study, 66 percent of affected German companies confirmed that AI has made attacks more effective. Thirty-six percent of employees fell for such attacks, with AI-generated messages appearing particularly convincing. Malicious links and email attachments each accounted for 45 percent of incidents.

Android Flaw and End of Updates for Older Models

Technical vulnerabilities remain a persistent concern. A flaw discovered in Android 16 allowed attackers to bypass PIN protection using a specific sequence of key presses. A patch has been rolling out since mid-July 2026. Another vulnerability in MediaTek chipsets enabled the extraction of PINs and cryptographic keys. Apple, meanwhile, closed the “DarkSword” exploit with iOS 26.3 — a vulnerability chain that had previously leveraged six zero-day flaws.

As of July 21, 2026, several older smartphone models lost their update support. A major manufacturer has stopped providing regular patches for devices such as the Galaxy A03s and A52s. Experts are urging companies to closely monitor their device inventories, noting that outdated software represents a significant entry point for ransomware groups. Approximately 32 percent of these groups are now linked to state-backed actors in China, Russia or Iran.

Advertisement

Outdated devices aren't the only security gap your organisation might be overlooking. Many UK employers are unaware that missing or incomplete risk assessments can leave them just as exposed to legal and operational threats. A free toolkit with 41 ready-to-use checklists helps you document workplace hazards properly and stay compliant. Download the free Risk Assessment Toolkit

Passkeys Gain Traction as Authentication Evolves

In response to the growing threats, more service providers are adopting modern security standards. In July 2026, major German email providers including GMX and WEB.DE began rolling out passkeys for their roughly 38 million users. Microsoft also plans to make passkeys the default for Entra ID starting in September 2026 and to phase out SMS-based authentication by February 2027.

Yet technology alone is not enough. Security analysts stress that behavioral detection and employee training remain the most effective defenses against modern cyberattacks. Current surveys, however, indicate that 63 percent of professionals still see significant gaps in their ability to identify AI-powered attacks.

Disclaimer regarding our articles: No investment advice, no buy or sell recommendation. Information on prices, companies, and markets is provided without guarantee; changes are possible at any time. Stock market transactions can lead to substantial losses. Our articles are created and reviewed in whole or in part automatically with the support of AI.

en | boerse | 69846798 |